GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,337 advisories
Filter by severity
OpenFGA Authorization Bypass
Moderate
CVE-2022-39352
was published
for
github.com/openfga/openfga
(Go)
Nov 8, 2022
Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local...
Moderate
Unreviewed
CVE-2022-2188
was published
Nov 7, 2022
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA),...
Moderate
Unreviewed
CVE-2022-20942
was published
Nov 4, 2022
Auth. (subscriber+) Broken Access Control vulnerability in David Cole Simple SEO plugin <= 1.8.12...
Moderate
Unreviewed
CVE-2022-36404
was published
Nov 4, 2022
A permissions issue existed. This issue was addressed with improved permission validation. This...
Moderate
Unreviewed
CVE-2022-42788
was published
Nov 2, 2022
OpenFGA Authorization Bypass via tupleset wildcard
Moderate
CVE-2022-39341
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
OpenFGA Authorization Bypass
Moderate
CVE-2022-39342
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
OpenFGA subject to Information Disclosure via streamed-list-objects endpoint
Moderate
CVE-2022-39340
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
Improper authorization in handler for custom URL scheme vulnerability in Lemon8 App for Android...
Moderate
Unreviewed
CVE-2022-41797
was published
Oct 24, 2022
Team scope authorization bypass when Post/Put request with :team_name in body, allows HTTP parameter pollution
Moderate
CVE-2022-31683
was published
for
github.com/concourse/concourse
(Go)
Oct 19, 2022
A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage...
Moderate
Unreviewed
CVE-2022-3585
was published
Oct 18, 2022
It was possible for a guest user to read a todo targeting an inaccessible note in Gitlab CE/EE...
Moderate
Unreviewed
CVE-2022-3330
was published
Oct 17, 2022
IBM Navigator Mobile Android 3.4.1.1 and 3.4.1.2 app could allow a local user to obtain sensitive...
Moderate
Unreviewed
CVE-2022-38388
was published
Oct 11, 2022
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control...
Moderate
Unreviewed
CVE-2022-34434
was published
Oct 11, 2022
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows...
Moderate
Unreviewed
CVE-2022-39873
was published
Oct 7, 2022
A Incorrect Authorization vulnerability in chkstat of SUSE Linux Enterprise Server 12-SP5;...
Moderate
Unreviewed
CVE-2022-31252
was published
Oct 6, 2022
Moodle Incorrect Authorization
Moderate
CVE-2021-40692
was published
for
moodle/moodle
(Composer)
Sep 30, 2022
Smart eVision has inadequate authorization for the database query function. A remote attacker...
Moderate
Unreviewed
CVE-2022-39029
was published
Sep 29, 2022
Smart eVision has insufficient authorization for task acquisition function. An unauthorized...
Moderate
Unreviewed
CVE-2022-39031
was published
Sep 29, 2022
Zammad 5.2.1 is vulnerable to Incorrect Access Control. Zammad's asset handling mechanism has...
Moderate
Unreviewed
CVE-2022-40816
was published
Sep 28, 2022
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0...
Moderate
Unreviewed
CVE-2022-3048
was published
Sep 27, 2022
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a...
Moderate
Unreviewed
CVE-2022-3057
was published
Sep 27, 2022
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195...
Moderate
Unreviewed
CVE-2022-3056
was published
Sep 27, 2022
Insufficient policy enforcement in Extensions API in Google Chrome prior to 105.0.5195.52 allowed...
Moderate
Unreviewed
CVE-2022-3047
was published
Sep 27, 2022
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a...
Moderate
Unreviewed
CVE-2022-3044
was published
Sep 27, 2022
ProTip!
Advisories are also available from the
GraphQL API