GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
25 advisories
Filter by severity
CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote...
Moderate
Unreviewed
CVE-2026-5302
was published
Apr 8, 2026
Sliver One-Click Remote Access: Insecure CORS & Unauthenticated MCP Interface
Moderate
CVE-2026-34227
was published
for
github.com/bishopfox/sliver
(Go)
Mar 31, 2026
MCP Java SDK has a Hardcoded Wildcard CORS (Access-Control-Allow-Origin: *)
Moderate
CVE-2026-34237
was published
for
io.modelcontextprotocol.sdk:mcp-core
(Maven)
Mar 30, 2026
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js...
Moderate
Unreviewed
CVE-2025-13984
was published
Jan 28, 2026
A CORS misconfiguration in Eramba Community and Enterprise Editions v3.26.0 allows an attacker...
Moderate
Unreviewed
CVE-2025-55462
was published
Jan 13, 2026
The issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1,...
Moderate
Unreviewed
CVE-2025-43392
was published
Nov 4, 2025
IBM Aspera Faspex 5.0.0 through 5.0.13.1 uses a cross-domain policy file that includes domains...
Moderate
Unreviewed
CVE-2023-37401
was published
Oct 9, 2025
Incorrect Cross-Origin Resource Sharing (CORS) configuration in Hiberus Sintra. Cross-Origin...
Moderate
Unreviewed
CVE-2025-41010
was published
Oct 2, 2025
This vulnerability affects Firefox < 143, Firefox ESR < 140.3, Thunderbird < 143, and Thunderbird...
Moderate
Unreviewed
CVE-2025-10529
was published
Sep 16, 2025
IBM Concert Software 1.0.0 through 1.1.0 uses cross-origin resource sharing (CORS) which could...
Moderate
Unreviewed
CVE-2025-27909
was published
Aug 18, 2025
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross...
Moderate
Unreviewed
CVE-2025-41363
was published
Jun 6, 2025
In IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04, a configuration error has been detected in cross...
Moderate
Unreviewed
CVE-2025-41366
was published
Jun 6, 2025
IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 uses Cross-Origin...
Moderate
Unreviewed
CVE-2024-22348
was published
Jan 20, 2025
IBM Security ReaQta 3.12 is vulnerable to cross-site scripting. This vulnerability allows a...
Moderate
Unreviewed
CVE-2024-45642
was published
Nov 14, 2024
In Gliffy Online an insecure configuration was discovered in versions before 4.14.0-6
Moderate
Unreviewed
CVE-2024-10315
was published
Nov 11, 2024
HyperView Geoportal Toolkit in versions though 8.2.4 does not restrict cross-domain requests when...
Moderate
Unreviewed
CVE-2024-6449
was published
Aug 28, 2024
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection...
Moderate
Unreviewed
CVE-2024-32862
was published
Aug 2, 2024
HCL DRYiCE Lucy (now AEX) is affected by a Cross Origin Resource Sharing (CORS) vulnerability....
Moderate
Unreviewed
CVE-2023-37526
was published
May 14, 2024
vantage6's CORS settings overly permissive
Moderate
CVE-2024-23823
was published
for
vantage6
(pip)
Mar 15, 2024
A potential attacker with access to the Westermo Lynx device would be able to execute...
Moderate
Unreviewed
CVE-2023-45213
was published
Feb 7, 2024
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an...
Moderate
Unreviewed
CVE-2023-50940
was published
Feb 2, 2024
Microsoft Edge for Android Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-21382
was published
Jan 26, 2024
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 ...
Moderate
Unreviewed
CVE-2023-25603
was published
Nov 14, 2023
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).
Moderate
Unreviewed
CVE-2023-23128
was published
Feb 1, 2023
ProTip!
Advisories are also available from the
GraphQL API