GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,005 advisories
Filter by severity
Improper access control in PAM JIT elevation in Devolutions Server 2024.1.6 and earlier allows an...
High
Unreviewed
CVE-2024-2915
was published
Mar 26, 2024
Broken access control in the component /admin/management/users of School Fees Management System...
High
Unreviewed
CVE-2023-49982
was published
Mar 21, 2024
An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to...
High
Unreviewed
CVE-2024-0199
was published
Mar 7, 2024
Deno arbitrary file descriptor close via `op_node_ipc_pipe()` leading to permission prompt bypass
High
CVE-2024-27933
was published
for
deno
(Rust)
Mar 6, 2024
Apache Archiva Incorrect Authorization vulnerability
High
CVE-2024-27138
was published
for
org.apache.archiva:archiva
(Maven)
Mar 1, 2024
Apache Archiva Incorrect Authorization vulnerability
High
CVE-2024-27139
was published
for
org.apache.archiva:archiva
(Maven)
Mar 1, 2024
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2023-42860
was published
Feb 21, 2024
Incorrect permissions in the installation directories for shared SystemLink Elixir based services...
High
Unreviewed
CVE-2024-1155
was published
Feb 20, 2024
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local...
High
Unreviewed
CVE-2024-1156
was published
Feb 20, 2024
Permission control vulnerability in the package management module.Successful exploitation of this...
High
Unreviewed
CVE-2023-52374
was published
Feb 18, 2024
The VerifiedBoot module has a vulnerability that may cause authentication errors.Successful...
High
Unreviewed
CVE-2023-52361
was published
Feb 18, 2024
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed...
High
Unreviewed
CVE-2024-1482
was published
Feb 14, 2024
OpenRefine JDBC Attack Vulnerability
High
CVE-2024-23833
was published
for
org.openrefine:database
(Maven)
Feb 12, 2024
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with...
High
Unreviewed
CVE-2023-51761
was published
Feb 9, 2024
IBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an...
High
Unreviewed
CVE-2023-47142
was published
Feb 2, 2024
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute...
High
Unreviewed
CVE-2024-22938
was published
Jan 30, 2024
Authorization vulnerability in the BootLoader module. Successful exploitation of this...
High
Unreviewed
CVE-2023-52111
was published
Jan 16, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 15.3 before 16.5.6...
High
Unreviewed
CVE-2023-4812
was published
Jan 12, 2024
SAP LT Replication Server - version S4CORE 103, S4CORE 104, S4CORE 105, S4CORE 106, S4CORE 107,...
High
Unreviewed
CVE-2024-21735
was published
Jan 9, 2024
The WP Mail Log WordPress plugin before 1.1.3 does not correctly authorize its REST API endpoints...
High
Unreviewed
CVE-2023-5644
was published
Dec 26, 2023
Passwork before 6.2.0 allows remote authenticated users to bypass 2FA by sending all one million...
High
Unreviewed
CVE-2023-49949
was published
Dec 26, 2023
The api /api/snapshot and /api/get_log_file would allow unauthenticated access.
It could allow a...
High
Unreviewed
CVE-2023-41314
was published
Dec 22, 2023
Velocity execution without script right through tree macro
High
CVE-2023-50732
was published
for
org.xwiki.platform:xwiki-platform-index-tree-macro
(Maven)
Dec 19, 2023
Apache Superset incorrect write permissions vulnerability
High
CVE-2023-49734
was published
for
apache-superset
(pip)
Dec 19, 2023
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an...
High
Unreviewed
CVE-2023-45185
was published
Dec 14, 2023
ProTip!
Advisories are also available from the
GraphQL API