GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,337 advisories
Filter by severity
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI...
Moderate
Unreviewed
CVE-2023-24512
was published
Apr 25, 2023
Improper access control in Odoo Community 13.0 and earlier and Odoo Enterprise 13.0 and earlier...
Moderate
Unreviewed
CVE-2021-44465
was published
Apr 25, 2023
An issue was discovered in Telindus Apsal 3.14.2022.235 b. Unauthorized actions that could modify...
Moderate
Unreviewed
CVE-2023-26097
was published
Apr 24, 2023
A CWE-863: Incorrect Authorization vulnerability exists that could allow access to device...
Moderate
Unreviewed
CVE-2023-25548
was published
Apr 18, 2023
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 ...
Moderate
Unreviewed
CVE-2023-2020
was published
Apr 18, 2023
Apache Superset vulnerable to Improper Authorization
Moderate
CVE-2023-27525
was published
for
apache-superset
(pip)
Apr 17, 2023
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated...
Moderate
Unreviewed
CVE-2023-25415
was published
Apr 11, 2023
Windows Lock Screen Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-28270
was published
Apr 11, 2023
Windows Boot Manager Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-28249
was published
Apr 11, 2023
An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5,...
Moderate
Unreviewed
CVE-2023-0319
was published
Apr 5, 2023
An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all...
Moderate
Unreviewed
CVE-2023-1071
was published
Apr 5, 2023
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 15.9.4,...
Moderate
Unreviewed
CVE-2023-1417
was published
Apr 5, 2023
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server...
Moderate
Unreviewed
CVE-2023-1603
was published
Apr 2, 2023
Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote...
Moderate
Unreviewed
CVE-2023-1202
was published
Apr 2, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-22251
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Potential network policy bypass when routing IPv6 traffic
Moderate
CVE-2023-27594
was published
for
github.com/cilium/cilium
(Go)
Mar 17, 2023
Windows SmartScreen Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-24880
was published
Mar 14, 2023
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0...
Moderate
Unreviewed
CVE-2022-4315
was published
Mar 9, 2023
OpenSearch has issue with fine-grained access control of indices backing data streams
Moderate
CVE-2022-41918
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Mar 7, 2023
The WPCode WordPress plugin before 2.0.7 does not have adequate privilege checks in place for...
Moderate
Unreviewed
CVE-2023-0328
was published
Mar 6, 2023
xwiki contains Incorrect Authorization
Moderate
CVE-2023-26056
was published
for
org.xwiki.platform:xwiki-platform-rendering-macro-context
(Maven)
Mar 3, 2023
Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an...
Moderate
Unreviewed
CVE-2023-0952
was published
Mar 1, 2023
A permissions issue was addressed with improved validation. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2023-23506
was published
Feb 27, 2023
A logic issue was addressed with improved state management. This issue is fixed in macOS Ventura...
Moderate
Unreviewed
CVE-2022-46704
was published
Feb 27, 2023
Supplementary groups are not set up properly in github.com/containerd/containerd
Moderate
CVE-2023-25173
was published
for
github.com/containerd/containerd
(Go)
Feb 16, 2023
ProTip!
Advisories are also available from the
GraphQL API