Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

524 advisories

Loading
Apache Pulsar Function Worker Incorrect Authorization vulnerability Moderate
CVE-2023-37579 was published for org.apache.pulsar:pulsar-functions-worker (Maven) Jul 12, 2023
Apache Pulsar Incorrect Authorization vulnerability Critical
CVE-2023-30429 was published for org.apache.pulsar:pulsar (Maven) Jul 12, 2023
Apache Airflow Incorrect Authorization vulnerability High
CVE-2023-35908 was published for apache-airflow (pip) Jul 12, 2023
sunSUNQ
Pimcore Customer Management Framework vulnerable to Improper Authorization in Rules Controller Moderate
CVE-2023-3574 was published for pimcore/customer-management-framework-bundle (Composer) Jul 10, 2023
aqngoc
Sentry CORS misconfiguration Moderate
CVE-2023-36829 was published for sentry (pip) Jul 6, 2023
andr0idp4r4n0id
Improper configuration of RBAC permissions obtaining cluster control permissions Critical
CVE-2023-33190 was published for github.com/labring/sealos (Go) Jun 30, 2023
DVKunion
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource Low
CVE-2023-3485 was published for go.temporal.io/server (Go) Jun 30, 2023
XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanel High
CVE-2023-35166 was published for org.xwiki.platform:xwiki-platform-help-ui (Maven) Jun 20, 2023
AWS CDK EKS overly permissive trust policies Moderate
CVE-2023-35165 was published for @aws-cdk/aws-eks (npm) Jun 19, 2023
twelvemo stefreak
Magento Open Source affected by Improper Input Validation Moderate
CVE-2023-22248 was published for magento/community-edition (Composer) Jun 15, 2023
Magento Open Source allows Incorrect Authorization Low
CVE-2023-29296 was published for magento/community-edition (Composer) Jun 15, 2023
Magento Open Source allows Incorrect Authorization Low
CVE-2023-29295 was published for magento/community-edition (Composer) Jun 15, 2023
Magento Open Source allows Incorrect Authorization Moderate
CVE-2023-29288 was published for magento/community-edition (Composer) Jun 15, 2023
Synapse has URL deny list bypass via oEmbed and image URLs when generating previews Moderate
CVE-2023-32683 was published for matrix-synapse (pip) Jun 6, 2023
Rancher users retain access after moving namespaces into projects they don't have access to High
CVE-2020-10676 was published for github.com/rancher/rancher (Go) Jun 6, 2023
Privilege escalation in XXL-Job High
CVE-2023-33779 was published for com.xuxueli:xxl-job (Maven) May 26, 2023
Mattermost Incorrect Authorization vulnerability High
CVE-2023-2515 was published for github.com/mattermost/mattermost-server/v6 (Go) May 12, 2023
Privilege escalation (PR)/RCE from account through class sheet Critical
CVE-2023-32069 was published for org.xwiki.platform:xwiki-platform-test-ui (Maven) May 11, 2023
OpenSearch issue with fine-grained access control during extremely rare race conditions Moderate
CVE-2023-31141 was published for org.opensearch.plugin:opensearch-security (Maven) May 9, 2023
On a compromised node, the fluid-csi service account can be used to modify node specs Moderate
CVE-2023-30840 was published for github.com/fluid-cloudnative/fluid (Go) May 9, 2023
Access bypass in Drupal core Moderate
CVE-2022-25274 was published for drupal/core (Composer) Apr 26, 2023
kiwi TCMS has possibility for user to update email address to unverified one Low
CVE-2023-30544 was published for kiwitcms (pip) Apr 24, 2023
Apache Superset vulnerable to Improper Authorization Moderate
CVE-2023-27525 was published for apache-superset (pip) Apr 17, 2023
Magento Open Source allows Incorrect Authorization Moderate
CVE-2023-22251 was published for magento/community-edition (Composer) Mar 27, 2023
Potential network policy bypass when routing IPv6 traffic Moderate
CVE-2023-27594 was published for github.com/cilium/cilium (Go) Mar 17, 2023
ysksuzuki
ProTip! Advisories are also available from the GraphQL API