GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
838 advisories
Filter by severity
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read...
High
Unreviewed
CVE-2023-20871
was published
Apr 25, 2023
Improper access control in reporting engine of Odoo Community 14.0 through 15.0, and Odoo...
High
Unreviewed
CVE-2021-23203
was published
Apr 25, 2023
Authentication Bypass in Hub Business integration in Devolutions Workspace Desktop 2023.1.1.3 and...
High
Unreviewed
CVE-2023-2257
was published
Apr 24, 2023
In AlarmManagerActivity of AlarmManagerActivity.java, there is a possible way to bypass...
High
Unreviewed
CVE-2023-20950
was published
Apr 19, 2023
A CWE-863: Incorrect Authorization vulnerability exists that could allow remote code execution...
High
Unreviewed
CVE-2023-25547
was published
Apr 18, 2023
LilyPond before 2.24 allows attackers to bypass the -dsafe protection mechanism via output-def...
High
Unreviewed
CVE-2020-17354
was published
Apr 16, 2023
An issue was discovered in SecurePoint UTM before 12.2.5.1. The firewall's endpoint at /spcgi.cgi...
High
Unreviewed
CVE-2023-22620
was published
Apr 13, 2023
A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 -...
High
Unreviewed
CVE-2022-40682
was published
Apr 11, 2023
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including...
High
Unreviewed
CVE-2022-43940
was published
Apr 3, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected...
High
Unreviewed
CVE-2022-27645
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected...
High
Unreviewed
CVE-2022-27642
was published
Mar 29, 2023
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access...
High
Unreviewed
CVE-2023-1144
was published
Mar 27, 2023
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated...
High
Unreviewed
CVE-2023-1136
was published
Mar 27, 2023
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote...
High
Unreviewed
CVE-2023-25017
was published
Mar 27, 2023
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions...
High
Unreviewed
CVE-2023-21035
was published
Mar 24, 2023
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data...
High
Unreviewed
CVE-2023-21034
was published
Mar 24, 2023
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible...
High
Unreviewed
CVE-2023-20975
was published
Mar 24, 2023
In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl.java, there is a possible...
High
Unreviewed
CVE-2023-20971
was published
Mar 24, 2023
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
High
Unreviewed
CVE-2023-23192
was published
Mar 23, 2023
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an...
High
Unreviewed
CVE-2023-25594
was published
Mar 22, 2023
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an...
High
Unreviewed
CVE-2023-25924
was published
Mar 22, 2023
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an...
High
Unreviewed
CVE-2023-25923
was published
Mar 21, 2023
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker...
High
Unreviewed
CVE-2022-45636
was published
Mar 21, 2023
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user...
High
Unreviewed
CVE-2023-0940
was published
Mar 20, 2023
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0...
High
Unreviewed
CVE-2023-22891
was published
Mar 8, 2023
ProTip!
Advisories are also available from the
GraphQL API