GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,462
Erlang
33
GitHub Actions
22
Go
2,159
Maven
5,000+
npm
3,820
NuGet
696
pip
3,502
Pub
12
RubyGems
903
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
221 advisories
Filter by severity
Garuda Linux performs an insecure user creation and authentication that allows any user to...
High
Unreviewed
CVE-2021-3784
was published
Oct 4, 2023
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This...
High
Unreviewed
CVE-2023-3037
was published
Oct 4, 2023
The vulnerability is the use of implicit PendingIntents without the PendingIntent.FLAG_IMMUTABLE...
High
Unreviewed
CVE-2023-44125
was published
Sep 27, 2023
The vulnerability is the use of implicit PendingIntents with the PendingIntent.FLAG_MUTABLE set...
High
Unreviewed
CVE-2023-44123
was published
Sep 27, 2023
Dell NetWorker, Version 19.7 has an improper authorization vulnerability in the NetWorker client...
High
Unreviewed
CVE-2023-28055
was published
Sep 27, 2023
A flaw was found in APICast, when 3Scale's OIDC module does not properly evaluate the response to...
High
Unreviewed
CVE-2023-0456
was published
Sep 27, 2023
** UNSUPPPORTED WHEN ASSIGNED ** Incorrect authorisation in ekorCCP and ekorRCI, which could...
High
Unreviewed
CVE-2022-47553
was published
Sep 19, 2023
A flaw was found in the Network Observability plugin for OpenShift console. Unless the Loki...
High
Unreviewed
CVE-2023-0813
was published
Sep 15, 2023
Transient DOS in WLAN Host while doing channel switch announcement (CSA), when a mobile station...
High
Unreviewed
CVE-2023-33019
was published
Sep 5, 2023
Transient DOS in WLAN Host when a mobile station receives invalid channel in CSA IE while doing...
High
Unreviewed
CVE-2023-28584
was published
Sep 5, 2023
Transient DOS in WLAN Host when an invalid channel (like channel out of range) is received in STA...
High
Unreviewed
CVE-2023-33020
was published
Sep 5, 2023
A vulnerability was found in subscription-manager that allows local privilege escalation due to...
High
Unreviewed
CVE-2023-3899
was published
Aug 23, 2023
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High
CVE-2023-3518
was published
for
github.com/hashicorp/consul
(Go)
Aug 9, 2023
The FULL - Customer plugin for WordPress is vulnerable to Arbitrary File Upload via the /install...
High
Unreviewed
CVE-2023-4243
was published
Aug 9, 2023
The ACL (Access Control List) of SAP Message Server - versions KERNEL 7.22, KERNEL 7.53, KERNEL 7...
High
Unreviewed
CVE-2023-37491
was published
Aug 8, 2023
Improper authorization on debug and artifact file downloads
High
CVE-2023-36826
was published
for
sentry
(pip)
Jul 25, 2023
A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video...
High
Unreviewed
CVE-2023-3805
was published
Jul 21, 2023
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below...
High
Unreviewed
CVE-2023-32707
was published
Jul 6, 2023
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as...
High
Unreviewed
CVE-2023-2534
was published
Jul 6, 2023
A CWE-285: Improper Authorization vulnerability exists that could cause Denial of Service against...
High
Unreviewed
CVE-2023-22610
was published
Jul 6, 2023
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a...
High
Unreviewed
CVE-2023-25517
was published
Jul 4, 2023
By changing the filename parameter in the request, an attacker could
delete any file with the...
High
Unreviewed
CVE-2023-29152
was published
Jun 8, 2023
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization...
High
Unreviewed
CVE-2020-36696
was published
Jun 7, 2023
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request...
High
Unreviewed
CVE-2022-40536
was published
Jun 6, 2023
Transient DOS due to improper authorization in Modem
High
Unreviewed
CVE-2022-40521
was published
Jun 6, 2023
ProTip!
Advisories are also available from the
GraphQL API