GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,618 advisories
Filter by severity
Apache Airflow vulnerable to sensitive information exposure
Moderate
CVE-2023-42663
was published
for
apache-airflow
(pip)
Oct 14, 2023
Apache Airflow vulnerable to privilege escalation
Moderate
CVE-2023-42792
was published
for
apache-airflow
(pip)
Oct 14, 2023
Defining resource name as integer may give unintended access in vantage6
Moderate
CVE-2023-28635
was published
for
vantage6
(pip)
Oct 13, 2023
Improper Access Control in vantage6
Moderate
CVE-2023-41882
was published
for
vantage6
(pip)
Oct 13, 2023
matrix-synapse vulnerable to denial of service due to malicious server ACL events
Moderate
CVE-2023-45129
was published
for
matrix-synapse
(pip)
Oct 10, 2023
Microsoft Common Data Model SDK Denial of Service Vulnerability
Moderate
CVE-2023-36566
was published
for
Microsoft.CommonDataModel.ObjectModel
(Maven)
Oct 10, 2023
Ansible may expose private key
Moderate
CVE-2023-4237
was published
for
ansible-core
(pip)
Oct 4, 2023
pretix potential IP address spoofing vulnerability
Moderate
CVE-2023-44463
was published
for
pretix
(pip)
Oct 2, 2023
Vyper's `_abi_decode` input not validated in complex expressions
Moderate
CVE-2023-42460
was published
for
vyper
(pip)
Sep 26, 2023
matrix-synapse vulnerable to improper validation of receipts allows forged read receipts
Moderate
CVE-2023-42453
was published
for
matrix-synapse
(pip)
Sep 26, 2023
OpenStack Barbican credential leak flaw
Moderate
CVE-2023-1633
was published
for
barbican
(pip)
Sep 24, 2023
OpenStack Barbican information disclosure vulnerability
Moderate
CVE-2023-1636
was published
for
barbican
(pip)
Sep 24, 2023
pgAdmin failed to properly control the server code
Moderate
CVE-2023-5002
was published
for
pgadmin4
(pip)
Sep 22, 2023
plone.rest vulnerable to Denial of Service when ++api++ is used many times
Moderate
CVE-2023-42457
was published
for
plone.rest
(pip)
Sep 21, 2023
Vyper has incorrect re-entrancy lock when key is empty string
Moderate
CVE-2023-42441
was published
for
vyper
(pip)
Sep 18, 2023
Gradio arbitrary file upload vulnerability
Moderate
CVE-2023-41626
was published
for
gradio
(pip)
Sep 16, 2023
Apache Airflow Incorrect Authorization vulnerability
Moderate
CVE-2023-40611
was published
for
apache-airflow
(pip)
Sep 12, 2023
Piccolo's current `BaseUser.login` implementation is vulnerable to time based user enumeration
Moderate
CVE-2023-41885
was published
for
piccolo
(pip)
Sep 12, 2023
Information disclosure in AccessControl
Moderate
CVE-2023-41050
was published
for
AccessControl
(pip)
Sep 7, 2023
Apache Superset has incorrect authorization check
Moderate
CVE-2023-32672
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset Improper Input Validation vulnerability
Moderate
CVE-2023-39265
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset Deserialization of Untrusted Data vulnerability
Moderate
CVE-2023-37941
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Moderate
CVE-2023-27526
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset vulnerable to improper data authorization
Moderate
CVE-2023-27523
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset Server Side Request Forgery vulnerability
Moderate
CVE-2023-36388
was published
for
apache-superset
(pip)
Sep 6, 2023
ProTip!
Advisories are also available from the
GraphQL API