GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,488 advisories
Filter by severity
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-8285
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2025-53514
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-53857
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-53910
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
High
CVE-2025-52931
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
High
CVE-2025-54525
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Improper Check for Unusual or Exceptional Conditions
Moderate
CVE-2025-54463
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
High
CVE-2025-44004
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-48731
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Low
CVE-2025-49221
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Confluence Plugin has Missing Authorization vulnerability
Moderate
CVE-2025-44001
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
OpenBao LDAP MFA Enforcement Bypass When Using Username As Alias
Moderate
CVE-2025-55001
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Login MFA Bypass of Rate Limiting and TOTP Token Reuse
Moderate
CVE-2025-55003
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao TOTP Secrets Engine Code Reuse
Moderate
CVE-2025-55000
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao has a Timing Side-Channel in the Userpass Auth Method
Low
CVE-2025-54999
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Userpass and LDAP User Lockout Bypass
Moderate
CVE-2025-54998
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
Privileged OpenBao Operator May Execute Code on the Underlying Host
Critical
CVE-2025-54997
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
OpenBao Root Namespace Operator May Elevate Token Privileges
High
CVE-2025-54996
was published
for
github.com/openbao/openbao
(Go)
Aug 8, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Ollama allows deletion of arbitrary files
Moderate
CVE-2025-44779
was published
for
github.com/ollama/ollama
(Go)
Aug 7, 2025
Duplicate Advisory: Denial of service via malicious preflight requests in github.com/rs/cors
Low
GHSA-vh9x-phq6-fx54
was published
for
github.com/rs/cors
(Go)
Aug 6, 2025
•
withdrawn
github.com/go-acme/lego/v4/acme/api does not enforce HTTPS
Low
CVE-2025-54799
was published
for
github.com/go-acme/lego
(Go)
Aug 6, 2025
HashiCorp Vault ldap auth method may not have correctly enforced MFA
Moderate
CVE-2025-6013
was published
for
github.com/hashicorp/vault
(Go)
Aug 6, 2025
Duplicate Advisory: CIRCL-Fourq: Missing and wrong validation can lead to incorrect results
Low
GHSA-522r-9946-fw43
was published
for
github.com/cloudflare/circl
(Go)
Aug 6, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API