GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
3,310 advisories
Filter by severity
There is an Access Control Vulnerability in some HikCentral Professional versions. This could...
High
Unreviewed
CVE-2025-39247
was published
Aug 29, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app...
Low
Unreviewed
CVE-2024-44271
was published
Aug 29, 2025
Incorrect access control in the endpoint /goform/ate of Tenda AC10 v4.0 firmware v16.03.10...
Moderate
Unreviewed
CVE-2025-57219
was published
Aug 28, 2025
Contao applies improper access control in the back end voters
Moderate
CVE-2025-57758
was published
for
contao/contao
(Composer)
Aug 28, 2025
Incorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260...
Moderate
Unreviewed
CVE-2025-25732
was published
Aug 26, 2025
Incorrect access control in the SPI Flash Chip of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside...
Moderate
Unreviewed
CVE-2025-25733
was published
Aug 26, 2025
A vulnerability has been found in SourceCodester Human Resource Information System 1.0. Affected...
Moderate
Unreviewed
CVE-2025-9476
was published
Aug 26, 2025
A flaw has been found in SourceCodester Human Resource Information System 1.0. Affected by this...
Moderate
Unreviewed
CVE-2025-9475
was published
Aug 26, 2025
A vulnerability was identified in GreenCMS up to 2.3.0603. This affects an unknown part of the...
Moderate
Unreviewed
CVE-2025-9415
was published
Aug 26, 2025
PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the getThemeFileContent function.
High
Unreviewed
CVE-2025-29421
was published
Aug 26, 2025
DASAN GPON ONU H660WM H660WMR210825 is susceptible to improper access control under its default...
Moderate
Unreviewed
CVE-2025-44178
was published
Aug 26, 2025
An issue was discovered in getrebuild/rebuild 4.0.4. The affected source code class is com...
Critical
Unreviewed
CVE-2025-50900
was published
Aug 26, 2025
Incorrect access control in the Maintenance module of D-Link DSL-7740C with firmware DSL7740C.V6...
Moderate
Unreviewed
CVE-2025-29520
was published
Aug 26, 2025
Incorrect access control in the component /cgi-bin/system_diagnostic_main.asp of DASAN GPON ONU...
Moderate
Unreviewed
CVE-2025-29524
was published
Aug 26, 2025
Incorrect access control in the prehandle function of Rebuild v3.7.7 allows attackers to bypass...
Moderate
Unreviewed
CVE-2024-46412
was published
Aug 26, 2025
Incorrect access control in the config.xgi function of D-Link DSL-7740C with firmware DSL7740C.V6...
Critical
Unreviewed
CVE-2025-29514
was published
Aug 25, 2025
Incorrect access control in the DELT_file.xgi endpoint of D-Link DSL-7740C with firmware DSL7740C...
Critical
Unreviewed
CVE-2025-29515
was published
Aug 25, 2025
A weakness has been identified in xuhuisheng lemon up to 1.13.0. This affects the function...
Moderate
Unreviewed
CVE-2025-9406
was published
Aug 25, 2025
A flaw has been found in YiFang CMS up to 2.0.5. This affects the function mergeMultipartUpload...
Moderate
Unreviewed
CVE-2025-9400
was published
Aug 25, 2025
A weakness has been identified in givanz Vvveb up to 1.0.7.2. Affected is an unknown function of...
Moderate
Unreviewed
CVE-2025-9397
was published
Aug 25, 2025
Voltronic Power ViewPower through 1.04-21353 and PowerShield Netguard before 1.04-23292 allows a...
Critical
Unreviewed
CVE-2022-43110
was published
Aug 22, 2025
An Insecure Direct Object Reference (IDOR) vulnerability in Reolink v4.54.0.4.20250526 allows...
Moderate
Unreviewed
CVE-2025-55621
was published
Aug 22, 2025
Incorrect access control in the doFilter function of my-site v1.0.2.RELEASE allows attackers to...
Critical
Unreviewed
CVE-2024-53496
was published
Aug 22, 2025
An Insecure Direct Object Reference (IDOR) vulnerability in Reolink Smart 2K+ Plug-in Wi-Fi Video...
Moderate
Unreviewed
CVE-2025-55626
was published
Aug 22, 2025
A discrepancy in the error message returned by the login function of Reolink Smart 2K+ Plug-in Wi...
High
Unreviewed
CVE-2025-55630
was published
Aug 22, 2025
ProTip!
Advisories are also available from the
GraphQL API