GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
835 advisories
Filter by severity
Hitachi Vantara Pentaho Business Analytics Server versions before 9.3.0.0, 9.2.0.4 and 8.3.0.27...
High
Unreviewed
CVE-2022-43770
was published
Jul 6, 2023
A CWE-285: Improper Authorization vulnerability exists that could cause Denial of Service against...
High
Unreviewed
CVE-2023-22610
was published
Jul 6, 2023
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a...
High
Unreviewed
CVE-2022-2155
was published
Jul 6, 2023
D-Link – G integrated Access Device4 Information Disclosure & Authorization Bypass. *Information...
High
Unreviewed
CVE-2022-36785
was published
Jul 6, 2023
An attacker with local access to the system can make unauthorized modifications of the security...
High
Unreviewed
CVE-2021-26360
was published
Jul 6, 2023
Inappropriate authorization vulnerability in the system apps. Successful exploitation of this...
High
Unreviewed
CVE-2022-48508
was published
Jul 6, 2023
there is a possible way to bypass the protected confirmation screen due to Failure to lock...
High
Unreviewed
CVE-2023-21225
was published
Jun 28, 2023
IBM Robotic Process Automation for Cloud Pak 21.0.1 through 21.0.7.3 and 23.0.0 through 23.0.3...
High
Unreviewed
CVE-2023-22593
was published
Jun 27, 2023
The Formidable Forms WordPress plugin before 6.3.1 does not adequately authorize the user or...
High
Unreviewed
CVE-2023-2877
was published
Jun 27, 2023
XML Signature Wrapping (XSW) in SAML-based Single Sign-on feature in TOPdesk v12.10.12 allows bad...
High
Unreviewed
CVE-2023-34923
was published
Jun 22, 2023
A logic error in SiLabs Z/IP Gateway SDK 7.18.02 and earlier allows authentication to be bypassed...
High
Unreviewed
CVE-2023-0971
was published
Jun 21, 2023
XWiki Platform vulnerable to privilege escalation (PR) from account through TipsPanel
High
CVE-2023-35166
was published
for
org.xwiki.platform:xwiki-platform-help-ui
(Maven)
Jun 20, 2023
nappropriate authorization vulnerability in the SettingsProvider module.Successful exploitation...
High
Unreviewed
CVE-2023-34161
was published
Jun 19, 2023
Adobe Commerce versions 2.4.6 (and earlier), 2.4.5-p2 (and earlier) and 2.4.4-p3 (and earlier)...
High
Unreviewed
CVE-2023-22248
was published
Jun 15, 2023
Improper Authorization in SSH server in Bosch VMS 11.0, 11.1.0, and 11.1.1 allows a remote...
High
Unreviewed
CVE-2023-28175
was published
Jun 15, 2023
IBM Security Guardium 11.3, 11.4, and 11.5 could allow a local user to obtain elevated privileges...
High
Unreviewed
CVE-2022-22307
was published
Jun 15, 2023
On affected versions of the CloudVision Portal improper access controls on the connection from...
High
Unreviewed
CVE-2023-24546
was published
Jun 13, 2023
Pydio Cells allows users by default to create so-called external users in order to share files...
High
Unreviewed
CVE-2023-32749
was published
Jun 8, 2023
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the...
High
Unreviewed
CVE-2020-36710
was published
Jun 7, 2023
An issue in the MVC Device Simulator of Sitecore Experience Platform (XP), Experience Manager (XM...
High
Unreviewed
CVE-2023-33651
was published
Jun 6, 2023
Memory corruption due to improper access control in kernel while processing a mapping request...
High
Unreviewed
CVE-2022-40529
was published
Jun 6, 2023
Memory Corruption in GPU Subsystem due to arbitrary command execution from GPU in privileged mode.
High
Unreviewed
CVE-2023-21670
was published
Jun 6, 2023
Rancher users retain access after moving namespaces into projects they don't have access to
High
CVE-2020-10676
was published
for
github.com/rancher/rancher
(Go)
Jun 6, 2023
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low...
High
Unreviewed
CVE-2023-3066
was published
Jun 5, 2023
Incorrect Authorization vulnerability in Mobatime web application allows Privilege Escalation,...
High
Unreviewed
CVE-2023-3033
was published
Jun 2, 2023
ProTip!
Advisories are also available from the
GraphQL API