GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
206 advisories
Filter by severity
A vulnerability, which was classified as critical, has been found in Xiamen Four Letter Video...
High
Unreviewed
CVE-2023-3805
was published
Jul 21, 2023
In versions of Splunk Enterprise below 9.0.5, 8.2.11, and 8.1.14, and Splunk Cloud Platform below...
High
Unreviewed
CVE-2023-32707
was published
Jul 6, 2023
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as...
High
Unreviewed
CVE-2023-2534
was published
Jul 6, 2023
A CWE-285: Improper Authorization vulnerability exists that could cause Denial of Service against...
High
Unreviewed
CVE-2023-22610
was published
Jul 6, 2023
NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (vGPU plugin), where a...
High
Unreviewed
CVE-2023-25517
was published
Jul 4, 2023
By changing the filename parameter in the request, an attacker could
delete any file with the...
High
Unreviewed
CVE-2023-29152
was published
Jun 8, 2023
The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to authorization...
High
Unreviewed
CVE-2020-36696
was published
Jun 7, 2023
Transient DOS due to improper authentication in modem while receiving plain TLB OTA request...
High
Unreviewed
CVE-2022-40536
was published
Jun 6, 2023
Transient DOS due to improper authorization in Modem
High
Unreviewed
CVE-2022-40521
was published
Jun 6, 2023
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2023-2496
was published
May 24, 2023
Improper access control in Samsung Core Service prior to version 2.1.00.36 allows attacker to...
High
Unreviewed
CVE-2023-21505
was published
May 4, 2023
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks...
High
Unreviewed
CVE-2023-28973
was published
Apr 18, 2023
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High
CVE-2023-1782
was published
for
github.com/hashicorp/nomad
(Go)
Apr 5, 2023
A vulnerability was found in kylin-activation and classified as critical. Affected by this issue...
High
Unreviewed
CVE-2023-1164
was published
Mar 3, 2023
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization,...
High
Unreviewed
CVE-2023-0822
was published
Feb 17, 2023
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass...
High
Unreviewed
CVE-2022-34446
was published
Feb 11, 2023
An improper access control vulnerability was identified in the Realtek audio driver. A local...
High
Unreviewed
CVE-2022-34405
was published
Jan 26, 2023
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
High
CVE-2022-21953
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in...
High
Unreviewed
CVE-2022-4701
was published
Jan 10, 2023
KubeOperator allows unauthorized access to system API
High
CVE-2023-22480
was published
for
github.com/KubeOperator/KubeOperator
(Go)
Jan 9, 2023
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical...
High
Unreviewed
CVE-2022-4879
was published
Jan 6, 2023
usememos/memos vulnerable to improper authorization
High
CVE-2022-4688
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
OpenFGA Authorization Bypass
High
CVE-2022-23542
was published
for
github.com/openfga/openfga
(Go)
Dec 20, 2022
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting...
High
Unreviewed
CVE-2022-2536
was published
Dec 15, 2022
Improper authorization in Exynos baseband prior to SMR DEC-2022 Release 1 allows remote attacker...
High
Unreviewed
CVE-2022-39902
was published
Dec 8, 2022
ProTip!
Advisories are also available from the
GraphQL API