GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
Moderate
CVE-2026-34227
was published
for
github.com/bishopfox/sliver
(Go)
Mar 31, 2026
Fleet: Unauthenticated Android device disenrollment vulnerability via Pub/Sub endpoint
Moderate
CVE-2026-24004
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 26, 2026
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL
Moderate
CVE-2025-55073
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost does not enforce MFA on WebSocket connections
Moderate
CVE-2025-55070
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 14, 2025
Mattermost Does Not Sanitize the Team Invite ID
Moderate
CVE-2025-47870
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Confluence Plugin is Missing Authentication for Critical Function
Moderate
CVE-2025-54478
was published
for
github.com/mattermost/mattermost-plugin-confluence
(Go)
Aug 11, 2025
Mattermost Missing Authentication for Critical Function
Moderate
CVE-2025-6226
was published
for
github.com/mattermost/mattermost-server
(Go)
Jul 18, 2025
OpenBao allows cancellation of root rekey and recovery rekey operations without authentication
Moderate
CVE-2025-52894
was published
for
github.com/openbao/openbao
(Go)
Jun 26, 2025
Navidrome uses MD5 hashing algorithm
Moderate
CVE-2024-41259
was published
for
github.com/navidrome/navidrome
(Go)
Aug 1, 2024
Unauthenticated Access to sensitive settings in Argo CD
Moderate
CVE-2024-37152
was published
for
github.com/argoproj/argo-cd/v2/server
(Go)
Jun 6, 2024
Etcd Gateway TLS authentication only applies to endpoints detected in DNS SRV records
Moderate
CVE-2020-15136
was published
for
go.etcd.io/etcd
(Go)
Jan 31, 2024
Cilium vulnerable to bypass of namespace restrictions in CiliumNetworkPolicy
Moderate
CVE-2023-41333
was published
for
github.com/cilium/cilium
(Go)
Sep 27, 2023
Missing Role Based Access Control for the REST handlers in bleve/http package
Moderate
CVE-2022-31022
was published
for
github.com/blevesearch/bleve
(Go)
Jun 3, 2022
Denial of service in Grafana
Moderate
CVE-2021-27358
was published
for
github.com/grafana/grafana
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API