GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
524 advisories
Filter by severity
Apache Pulsar Function Worker Incorrect Authorization vulnerability
Moderate
CVE-2023-37579
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Jul 12, 2023
Apache Pulsar Incorrect Authorization vulnerability
Critical
CVE-2023-30429
was published
for
org.apache.pulsar:pulsar
(Maven)
Jul 12, 2023
Apache Airflow Incorrect Authorization vulnerability
High
CVE-2023-35908
was published
for
apache-airflow
(pip)
Jul 12, 2023
Pimcore Customer Management Framework vulnerable to Improper Authorization in Rules Controller
Moderate
CVE-2023-3574
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jul 10, 2023
Improper configuration of RBAC permissions obtaining cluster control permissions
Critical
CVE-2023-33190
was published
for
github.com/labring/sealos
(Go)
Jun 30, 2023
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource
Low
CVE-2023-3485
was published
for
go.temporal.io/server
(Go)
Jun 30, 2023
XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanel
High
CVE-2023-35166
was published
for
org.xwiki.platform:xwiki-platform-help-ui
(Maven)
Jun 20, 2023
AWS CDK EKS overly permissive trust policies
Moderate
CVE-2023-35165
was published
for
@aws-cdk/aws-eks
(npm)
Jun 19, 2023
Magento Open Source affected by Improper Input Validation
Moderate
CVE-2023-22248
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29296
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29295
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-29288
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews
Moderate
CVE-2023-32683
was published
for
matrix-synapse
(pip)
Jun 6, 2023
Rancher users retain access after moving namespaces into projects they don't have access to
High
CVE-2020-10676
was published
for
github.com/rancher/rancher
(Go)
Jun 6, 2023
Privilege escalation in XXL-Job
High
CVE-2023-33779
was published
for
com.xuxueli:xxl-job
(Maven)
May 26, 2023
Mattermost Incorrect Authorization vulnerability
High
CVE-2023-2515
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
May 12, 2023
Privilege escalation (PR)/RCE from account through class sheet
Critical
CVE-2023-32069
was published
for
org.xwiki.platform:xwiki-platform-test-ui
(Maven)
May 11, 2023
OpenSearch issue with fine-grained access control during extremely rare race conditions
Moderate
CVE-2023-31141
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
May 9, 2023
On a compromised node, the fluid-csi service account can be used to modify node specs
Moderate
CVE-2023-30840
was published
for
github.com/fluid-cloudnative/fluid
(Go)
May 9, 2023
Access bypass in Drupal core
Moderate
CVE-2022-25274
was published
for
drupal/core
(Composer)
Apr 26, 2023
kiwi TCMS has possibility for user to update email address to unverified one
Low
CVE-2023-30544
was published
for
kiwitcms
(pip)
Apr 24, 2023
Apache Superset vulnerable to Improper Authorization
Moderate
CVE-2023-27525
was published
for
apache-superset
(pip)
Apr 17, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-22251
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Potential network policy bypass when routing IPv6 traffic
Moderate
CVE-2023-27594
was published
for
github.com/cilium/cilium
(Go)
Mar 17, 2023
ProTip!
Advisories are also available from the
GraphQL API