GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,337 advisories
Filter by severity
A vulnerability in the classic access control list (ACL) compression feature of Cisco IOS XR...
Moderate
Unreviewed
CVE-2023-20190
was published
Sep 13, 2023
Apache Airflow Incorrect Authorization vulnerability
Moderate
CVE-2023-40611
was published
for
apache-airflow
(pip)
Sep 12, 2023
An issue was discovered in Samsung Exynos Mobile Processor, Automotive Processor, and Modem ...
Moderate
Unreviewed
CVE-2023-37367
was published
Sep 8, 2023
A vulnerability in the secure boot implementation on affected Aruba 9200 and 9000 Series...
Moderate
Unreviewed
CVE-2023-38486
was published
Sep 6, 2023
Apache Superset has incorrect authorization check
Moderate
CVE-2023-32672
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset has improper default REST API permission for Gamma users
Moderate
CVE-2023-36387
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset vulnerable to improper data authorization
Moderate
CVE-2023-27523
was published
for
apache-superset
(pip)
Sep 6, 2023
Apache Superset users may incorrectly create resources using the import charts feature
Moderate
CVE-2023-27526
was published
for
apache-superset
(pip)
Sep 6, 2023
The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage...
Moderate
Unreviewed
CVE-2023-3814
was published
Sep 4, 2023
The User Activity Log WordPress plugin before 1.6.6 lacks proper authorisation when exporting its...
Moderate
Unreviewed
CVE-2023-4269
was published
Sep 4, 2023
An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5,...
Moderate
Unreviewed
CVE-2023-0120
was published
Sep 1, 2023
An improper authorization vulnerability exists where an authenticated,
low privileged remote...
Moderate
Unreviewed
CVE-2023-3253
was published
Aug 29, 2023
An issue was discovered in TECHView LA5570 Wireless Gateway 1.0.19_T53, allows physical attackers...
Moderate
Unreviewed
CVE-2023-34724
was published
Aug 29, 2023
A vulnerability has been identified in the ioLogik 4000 Series (ioLogik E4200) firmware versions...
Moderate
Unreviewed
CVE-2023-4227
was published
Aug 24, 2023
In Cacti 1.2.19, there is an authentication bypass in the web login functionality because of...
Moderate
Unreviewed
CVE-2022-48538
was published
Aug 22, 2023
OpenNMS privilege escalation vulnerability
Moderate
CVE-2023-40315
was published
for
org.opennms:opennms-webapp-rest
(Maven)
Aug 17, 2023
Mattermost does not validate requesting user permissions before updating admin details
Moderate
CVE-2023-4107
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows...
Moderate
Unreviewed
CVE-2023-28714
was published
Aug 11, 2023
1Panel Arbitrary File Download vulnerability
Moderate
CVE-2023-39965
was published
for
github.com/1Panel-dev/1Panel
(Go)
Aug 10, 2023
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.56.6?allows local...
Moderate
Unreviewed
CVE-2023-30705
was published
Aug 10, 2023
An access control vulnerability was found, due to the restrictions that are applied on actual...
Moderate
Unreviewed
CVE-2023-24471
was published
Aug 9, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-38209
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
The FULL - Customer plugin for WordPress is vulnerable to Information Disclosure via the /health...
Moderate
Unreviewed
CVE-2023-4242
was published
Aug 9, 2023
SAP NetWeaver Application Server ABAP and ABAP Platform - versions SAP_BASIS 700, SAP_BASIS 701,...
Moderate
Unreviewed
CVE-2023-37492
was published
Aug 8, 2023
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user...
Moderate
Unreviewed
CVE-2023-4194
was published
Aug 7, 2023
ProTip!
Advisories are also available from the
GraphQL API