GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,464 advisories
Filter by severity
Magento Improper Access Control vulnerability
Low
CVE-2025-24429
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24436
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Low
CVE-2025-24430
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24435
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24424
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Incorrect Authorization vulnerability
Moderate
CVE-2025-24421
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24413
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Information Exposure vulnerability
Moderate
CVE-2025-24408
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
High
CVE-2025-24411
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24417
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24416
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24412
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Adobe Commerce Improper Authorization vulnerability
High
CVE-2025-24409
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24410
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Adobe Commerce Path Traversal
High
CVE-2025-24406
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24414
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24415
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
Connect-CMS information that is restricted to viewing is visible
High
GHSA-2237-5r9w-vm8j
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
Connect-CMS Access control vulnerability
Moderate
GHSA-5rjc-jc28-cwgg
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
Pimcore Admin Classic Bundle allows user enumeration
Moderate
CVE-2025-24980
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Feb 7, 2025
Withdrawn Advisory: Sylius allows unrestricted brute-force attacks on user accounts
Moderate
CVE-2024-57610
was published
for
sylius/sylius
(Composer)
Feb 6, 2025
•
withdrawn
Multiple rtmpdump vulnerabilities
Critical
GHSA-vrpv-vw92-328g
was published
for
rudloff/rtmpdump-bin
(Composer)
Feb 6, 2025
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
Browsershot Local File Inclusion
Moderate
CVE-2025-1026
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
ProTip!
Advisories are also available from the
GraphQL API