GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,005 advisories
Filter by severity
This vulnerability allows network-adjacent attackers to bypass authentication on affected...
High
Unreviewed
CVE-2022-27642
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to bypass authentication on affected...
High
Unreviewed
CVE-2022-27645
was published
Mar 29, 2023
Delta Electronics InfraSuite Device Master versions prior to 1.0.5 contains an improper access...
High
Unreviewed
CVE-2023-1144
was published
Mar 27, 2023
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an unauthenticated...
High
Unreviewed
CVE-2023-1136
was published
Mar 27, 2023
RIFARTEK IOT Wall has a vulnerability of incorrect authorization. An authenticated remote...
High
Unreviewed
CVE-2023-25017
was published
Mar 27, 2023
In multiple functions of BackupHelper.java, there is a possible way for an app to get permissions...
High
Unreviewed
CVE-2023-21035
was published
Mar 24, 2023
In multiple functions of SensorService.cpp, there is a possible access of accurate sensor data...
High
Unreviewed
CVE-2023-21034
was published
Mar 24, 2023
In getAvailabilityStatus of EnableContentCapturePreferenceController.java, there is a possible...
High
Unreviewed
CVE-2023-20975
was published
Mar 24, 2023
In updatePermissionTreeSourcePackage of PermissionManagerServiceImpl.java, there is a possible...
High
Unreviewed
CVE-2023-20971
was published
Mar 24, 2023
IS Decisions UserLock MFA 11.01 is vulnerable to authentication bypass using scheduled task.
High
Unreviewed
CVE-2023-23192
was published
Mar 23, 2023
A vulnerability in the web-based management interface of ClearPass Policy Manager allows an...
High
Unreviewed
CVE-2023-25594
was published
Mar 22, 2023
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an...
High
Unreviewed
CVE-2023-25924
was published
Mar 22, 2023
IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 could allow an...
High
Unreviewed
CVE-2023-25923
was published
Mar 21, 2023
An issue discovered in MEGAFEIS, BOFEI DBD+ Application for IOS & Android v1.4.4 allows attacker...
High
Unreviewed
CVE-2022-45636
was published
Mar 21, 2023
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user...
High
Unreviewed
CVE-2023-0940
was published
Mar 20, 2023
On a compromised node, the virt-handler service account can be used to modify all node specs
High
CVE-2023-26484
was published
for
kubevirt.io/kubevirt
(Go)
Mar 16, 2023
Incorrect Authorization in Jenkins Core
High
CVE-2023-27899
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0...
High
Unreviewed
CVE-2023-22891
was published
Mar 8, 2023
A vulnerability was found in kylin-activation and classified as critical. Affected by this issue...
High
Unreviewed
CVE-2023-1164
was published
Mar 3, 2023
api-platform/core's secured properties may be accessible within collections
High
CVE-2023-25575
was published
for
api-platform/core
(Composer)
Feb 28, 2023
An issue was discovered in the A4N (Aremis 4 Nomad) application 1.5.0 for Android. It possesses...
High
Unreviewed
CVE-2022-34908
was published
Feb 27, 2023
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3...
High
Unreviewed
CVE-2023-23918
was published
Feb 23, 2023
Vulnerabilities have been identified that, collectively, allow a standard Windows user to perform...
High
Unreviewed
CVE-2023-24485
was published
Feb 16, 2023
Microsoft Publisher Security Features Bypass Vulnerability
High
Unreviewed
CVE-2023-21715
was published
Feb 14, 2023
The AMS module has a vulnerability of lacking permission verification in APIs.Successful...
High
Unreviewed
CVE-2022-48302
was published
Feb 9, 2023
ProTip!
Advisories are also available from the
GraphQL API