GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
764 advisories
Filter by severity
Improper Authorization in modoboa
Critical
CVE-2023-2227
was published
for
modoboa
(pip)
Apr 21, 2023
An Improper Authorization vulnerability in the 'sysmanctl' shell command of Juniper Networks...
High
Unreviewed
CVE-2023-28973
was published
Apr 18, 2023
Improper Authorization vulnerability in ForgeRock Inc. Access Management allows Authentication...
Critical
Unreviewed
CVE-2022-3748
was published
Apr 14, 2023
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High
CVE-2023-1782
was published
for
github.com/hashicorp/nomad
(Go)
Apr 5, 2023
Improper authorization in Gitlab EE affecting all versions from 12.3.0 before 15.8.5, all...
Moderate
Unreviewed
CVE-2023-1167
was published
Apr 5, 2023
HashiCorp Vault's PKI mount vulnerable to denial of service
Moderate
CVE-2023-0665
was published
for
github.com/hashicorp/vault
(Go)
Mar 30, 2023
A vulnerability was found in the device-mapper-multipath. The device-mapper-multipath allows...
High
Unreviewed
CVE-2022-3787
was published
Mar 29, 2023
Moodle may allow students to bypass sequential navigation during a quiz attempt
Moderate
CVE-2022-40208
was published
for
moodle/moodle
(Composer)
Mar 24, 2023
Potential network policy bypass when routing IPv6 traffic
Moderate
CVE-2023-27594
was published
for
github.com/cilium/cilium
(Go)
Mar 17, 2023
Improper Authorization in nilsteampassnet/teampass
Moderate
CVE-2023-1463
was published
for
nilsteampassnet/teampass
(Composer)
Mar 17, 2023
The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper...
Critical
Unreviewed
CVE-2023-1256
was published
Mar 16, 2023
Wallabag Improper Authorization vulnerability
Moderate
CVE-2023-0734
was published
for
wallabag/wallabag
(Composer)
Mar 5, 2023
A vulnerability was found in kylin-activation and classified as critical. Affected by this issue...
High
Unreviewed
CVE-2023-1164
was published
Mar 3, 2023
Pixelfed may allow unauthorized actor to view private posts
Moderate
CVE-2023-0914
was published
for
pixelfed/pixelfed
(Composer)
Feb 19, 2023
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization,...
High
Unreviewed
CVE-2023-0822
was published
Feb 17, 2023
PowerPath Management Appliance with versions 3.3 & 3.2* contains Authorization Bypass...
High
Unreviewed
CVE-2022-34446
was published
Feb 11, 2023
Because the web management interface for Unified Intents' Unified Remote solution does not itself...
Critical
Unreviewed
CVE-2022-3229
was published
Feb 7, 2023
Improper Authorization in GitHub repository phpipam/phpipam prior to v1.5.1.
Moderate
Unreviewed
CVE-2023-0678
was published
Feb 4, 2023
wallabag contains Improper Authorization via export feature
Moderate
CVE-2023-0609
was published
for
wallabag/wallabag
(Composer)
Feb 2, 2023
Symfony storing cookie headers in HttpCache
Moderate
CVE-2022-24894
was published
for
symfony/http-kernel
(Composer)
Feb 1, 2023
Withdrawn: wallabag subject to Improper Authorization via annotations
Moderate
GHSA-xrw3-wqph-3fxg
was published
for
wallabag/wallabag
(Composer)
Feb 1, 2023
•
withdrawn
Withdrawn: wallabag subject to Improper Authorization
Moderate
GHSA-h45f-rjvw-2rv2
was published
for
wallabag/wallabag
(Composer)
Feb 1, 2023
•
withdrawn
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to...
Low
Unreviewed
CVE-2022-4062
was published
Feb 1, 2023
An improper access control vulnerability was identified in the Realtek audio driver. A local...
High
Unreviewed
CVE-2022-34405
was published
Jan 26, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to...
Moderate
Unreviewed
CVE-2022-3740
was published
Jan 26, 2023
ProTip!
Advisories are also available from the
GraphQL API