GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,005 advisories
Filter by severity
Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted...
High
Unreviewed
CVE-2023-3590
was published
Jul 17, 2023
A hidden API exists in TapHome's core platform before version 2023.2 that allows an authenticated...
High
Unreviewed
CVE-2023-2759
was published
Jul 17, 2023
In getCurrentState of OneTimePermissionUserManager.java, there is a possible way to hold one-time...
High
Unreviewed
CVE-2023-21254
was published
Jul 13, 2023
In showNextSecurityScreenOrFinish of KeyguardSecurityContainerController.java, there is a...
High
Unreviewed
CVE-2023-21245
was published
Jul 13, 2023
In SettingsHomepageActivity.java, there is a possible way to launch arbitrary activities via...
High
Unreviewed
CVE-2023-21256
was published
Jul 13, 2023
Apache Pulsar Broker's Rest Producer vulnerable to Incorrect Authorization
High
CVE-2023-30428
was published
for
org.apache.pulsar:pulsar-broker
(Maven)
Jul 12, 2023
Apache Airflow Incorrect Authorization vulnerability
High
CVE-2023-35908
was published
for
apache-airflow
(pip)
Jul 12, 2023
SGUDA U-Lock central lock control service’s lock management function has incorrect authorization....
High
Unreviewed
CVE-2022-46307
was published
Jul 6, 2023
SGUDA U-Lock central lock control service’s user management function has incorrect authorization....
High
Unreviewed
CVE-2022-46308
was published
Jul 6, 2023
Improper Authorization vulnerability in OTRS AG OTRS 8 (Websocket API backend) allows any as...
High
Unreviewed
CVE-2023-2534
was published
Jul 6, 2023
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27...
High
Unreviewed
CVE-2022-43770
was published
Jul 6, 2023
A CWE-285: Improper Authorization vulnerability exists that could cause Denial of Service against...
High
Unreviewed
CVE-2023-22610
was published
Jul 6, 2023
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a...
High
Unreviewed
CVE-2022-2155
was published
Jul 6, 2023
D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information...
High
Unreviewed
CVE-2022-36785
was published
Jul 6, 2023
An attacker with local access to the system can make unauthorized modifications of the security...
High
Unreviewed
CVE-2021-26360
was published
Jul 6, 2023
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this...
High
Unreviewed
CVE-2022-48508
was published
Jul 6, 2023
there is a possible way to bypass the protected confirmation screen due to Failure to lock...
High
Unreviewed
CVE-2023-21225
was published
Jun 28, 2023
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3...
High
Unreviewed
CVE-2023-22593
was published
Jun 27, 2023
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or...
High
Unreviewed
CVE-2023-2877
was published
Jun 27, 2023
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service...
High
Unreviewed
CVE-2023-34148
was published
Jun 27, 2023
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service...
High
Unreviewed
CVE-2023-34146
was published
Jun 27, 2023
An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service...
High
Unreviewed
CVE-2023-34147
was published
Jun 27, 2023
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for...
High
Unreviewed
CVE-2023-32353
was published
Jun 23, 2023
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad...
High
Unreviewed
CVE-2023-34923
was published
Jun 22, 2023
An issue was discovered in /cgi-bin/adm.cgi in WavLink WavRouter version RPT70HA1.x, allows...
High
Unreviewed
CVE-2023-29708
was published
Jun 22, 2023
ProTip!
Advisories are also available from the
GraphQL API