GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
768 advisories
Filter by severity
The parent process would not properly check whether the Speech Synthesis feature is enabled, when...
Moderate
Unreviewed
CVE-2022-29913
was published
Dec 22, 2022
usememos/memos vulnerable to improper authorization
High
CVE-2022-4688
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos vulnerable to Improper Authorization
Moderate
CVE-2022-4802
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4798
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4804
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4811
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit...
Moderate
Unreviewed
CVE-2022-45874
was published
Dec 28, 2022
Froxlor Improper Authorization vulnerability
Moderate
CVE-2022-4868
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical...
High
Unreviewed
CVE-2022-4879
was published
Jan 6, 2023
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard. This...
Moderate
Unreviewed
CVE-2015-10033
was published
Jan 9, 2023
KubeOperator allows unauthorized access to system API
High
CVE-2023-22480
was published
for
github.com/KubeOperator/KubeOperator
(Go)
Jan 9, 2023
The Royal Elementor Addons plugin for WordPress is vulnerable to insufficient access control in...
High
Unreviewed
CVE-2022-4701
was published
Jan 10, 2023
Improper Authorization in grumpydictator/firefly-iii
Moderate
CVE-2023-0298
was published
for
grumpydictator/firefly-iii
(Composer)
Jan 14, 2023
Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster
High
CVE-2022-21953
was published
for
github.com/rancher/rancher
(Go)
Jan 25, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to...
Moderate
Unreviewed
CVE-2022-3740
was published
Jan 26, 2023
An improper access control vulnerability was identified in the Realtek audio driver. A local...
High
Unreviewed
CVE-2022-34405
was published
Jan 26, 2023
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to...
Low
Unreviewed
CVE-2022-4062
was published
Feb 1, 2023
Withdrawn: wallabag subject to Improper Authorization
Moderate
GHSA-h45f-rjvw-2rv2
was published
for
wallabag/wallabag
(Composer)
Feb 1, 2023
•
withdrawn
Withdrawn: wallabag subject to Improper Authorization via annotations
Moderate
GHSA-xrw3-wqph-3fxg
was published
for
wallabag/wallabag
(Composer)
Feb 1, 2023
•
withdrawn
Symfony storing cookie headers in HttpCache
Moderate
CVE-2022-24894
was published
for
symfony/http-kernel
(Composer)
Feb 1, 2023
wallabag contains Improper Authorization via export feature
Moderate
CVE-2023-0609
was published
for
wallabag/wallabag
(Composer)
Feb 2, 2023
Improper Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
Moderate
Unreviewed
CVE-2023-0678
was published
Feb 4, 2023
Because the web management interface for Unified Intents' Unified Remote solution does not itself...
Critical
Unreviewed
CVE-2022-3229
was published
Feb 7, 2023
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass...
High
Unreviewed
CVE-2022-34446
was published
Feb 11, 2023
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization,...
High
Unreviewed
CVE-2023-0822
was published
Feb 17, 2023
ProTip!
Advisories are also available from the
GraphQL API