GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,834 advisories
Filter by severity
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard...
Critical
Unreviewed
CVE-2023-47267
was published
Dec 20, 2023
A privilege escalation vulnerability in GitLab EE affecting all versions from 16.0 prior to 16.4...
Moderate
Unreviewed
CVE-2023-3907
was published
Dec 18, 2023
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an...
Low
Unreviewed
CVE-2023-6793
was published
Dec 13, 2023
Improper Privilege Management in sap-xssec
Critical
CVE-2023-50423
was published
for
sap-xssec
(pip)
Dec 13, 2023
Improper Privilege Management in github.com/sap/cloud-security-client-go
Critical
CVE-2023-50424
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 13, 2023
Improper JWT Signature Validation in SAP Security Services Library
Critical
CVE-2023-50422
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 13, 2023
An issue was discovered in BeyondTrust Privilege Management for Windows through 5.6. When adding...
High
Unreviewed
CVE-2020-12615
was published
Dec 12, 2023
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x...
High
Unreviewed
CVE-2023-41119
was published
Dec 12, 2023
Escalation of privileges in @sap/xssec
Critical
CVE-2023-49583
was published
for
@sap/xssec
(npm)
Dec 12, 2023
Duplicate Advisory: Privilege escalation in sap/cloud-security-client-go
Critical
GHSA-92cg-ghq6-9587
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Improper JWT Signature Validation in SAP Security Services Library
Critical
GHSA-gcgw-q47m-prvj
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Privilege escalation in sap-xssec
Critical
GHSA-p99h-pfg6-qrfg
was published
for
sap-xssec
(pip)
Dec 12, 2023
•
withdrawn
An issue was found in CPython 3.12.0 `subprocess` module on POSIX platforms. The issue was fixed...
Moderate
Unreviewed
CVE-2023-6507
was published
Dec 8, 2023
there is a possible permanent DoS or way for the modem to boot unverified firmware due to a logic...
Moderate
Unreviewed
CVE-2023-48406
was published
Dec 8, 2023
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices'...
High
Unreviewed
CVE-2023-39167
was published
Dec 7, 2023
An Improper Privilege Management vulnerability exists in HyperCloud that will impact the ability...
Moderate
Unreviewed
CVE-2023-45083
was published
Dec 5, 2023
An issue was discovered in Huddly HuddlyCameraService before version 8.0.7, not including version...
High
Unreviewed
CVE-2023-45253
was published
Dec 1, 2023
In Progress MOVEit Transfer versions released before 2022.0.9 (14.0.9), 2022.1.10 (14.1.10),...
High
Unreviewed
CVE-2023-6218
was published
Nov 29, 2023
The FACSChorus software does not properly assign data access privileges for operating system user...
Low
Unreviewed
CVE-2023-29066
was published
Nov 28, 2023
Improper Privilege Management vulnerability in ESKOM Computer e-municipality module allows...
High
Unreviewed
CVE-2023-6150
was published
Nov 28, 2023
Improper Privilege Management vulnerability in ESKOM Computer e-municipality module allows...
High
Unreviewed
CVE-2023-6151
was published
Nov 28, 2023
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series...
Moderate
Unreviewed
CVE-2023-37925
was published
Nov 28, 2023
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series...
Moderate
Unreviewed
CVE-2023-5797
was published
Nov 28, 2023
An improper privilege management vulnerability in the hotspot feature of the Zyxel USG FLEX...
Moderate
Unreviewed
CVE-2023-5960
was published
Nov 28, 2023
An improper privilege management vulnerability in the ZySH of the Zyxel ATP series firmware...
Moderate
Unreviewed
CVE-2023-5650
was published
Nov 28, 2023
ProTip!
Advisories are also available from the
GraphQL API