GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
768 advisories
Filter by severity
Microsoft Dynamics 365 (On-Premises) Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-30061
was published
Jul 9, 2024
OpenSearch Observability does not properly restrict access to private tenant resources
Low
CVE-2024-39901
was published
for
org.opensearch.plugin:opensearch-observability
(Maven)
Jul 10, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). ...
Moderate
Unreviewed
CVE-2024-21137
was published
Jul 17, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21166
was published
Jul 17, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21179
was published
Jul 17, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2024-21159
was published
Jul 17, 2024
The issue was addressed with improved restriction of data container access. This issue is fixed...
High
Unreviewed
CVE-2024-40783
was published
Jul 30, 2024
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6, macOS...
Moderate
Unreviewed
CVE-2024-40807
was published
Jul 30, 2024
A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in...
High
Unreviewed
CVE-2024-40814
was published
Jul 30, 2024
Bostr Improper Authorization vulnerability
Moderate
CVE-2024-41962
was published
for
bostr
(npm)
Aug 2, 2024
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an...
Critical
Unreviewed
CVE-2024-36130
was published
Aug 7, 2024
Jenkins does not perform a permission check in an HTTP endpoint
Moderate
CVE-2024-43045
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Aug 7, 2024
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified...
Moderate
Unreviewed
CVE-2024-7578
was published
Aug 7, 2024
Access permission verification vulnerability in the Contacts module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-42032
was published
Aug 8, 2024
Access permission verification vulnerability in the Notepad module
Impact: Successful...
Low
Unreviewed
CVE-2024-42036
was published
Aug 8, 2024
OpenFGA Authorization Bypass
High
CVE-2024-42473
was published
for
github.com/openfga/openfga
(Go)
Aug 9, 2024
"Hot" backup files may be downloaded by underprivileged users, if they are capable of acquiring a...
Moderate
Unreviewed
CVE-2024-6384
was published
Aug 13, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39405
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39404
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization leads to Security feature bypass
Moderate
CVE-2024-39417
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Access Control Leads to Privilege escalation
Moderate
CVE-2024-39419
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization leads to Security feature bypass
Moderate
CVE-2024-39416
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization Leading to Security feature bypass
Moderate
CVE-2024-39415
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization leads to security feature bypass
Moderate
CVE-2024-39411
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Improper Authorization vulnerability
Moderate
CVE-2024-39418
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
ProTip!
Advisories are also available from the
GraphQL API