GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,066 advisories
Filter by severity
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote...
Moderate
Unreviewed
CVE-2024-31402
was published
Jun 11, 2024
Evmos allows unvested token delegations
Moderate
CVE-2024-37154
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6...
Moderate
Unreviewed
CVE-2024-23669
was published
Jun 5, 2024
TYPO3 Broken Access Control in Import Module
Moderate
GHSA-g776-759r-pf6x
was published
for
typo3/cms-core
(Composer)
May 30, 2024
An authorization vulnerability exists within GitLab from versions 16.10 before 16.10.6, 16.11...
Moderate
Unreviewed
CVE-2024-5258
was published
May 23, 2024
Incorrect Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter ...
Moderate
Unreviewed
CVE-2024-34434
was published
May 17, 2024
Grafana API IDOR
Moderate
CVE-2022-21713
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
Apache Superset Incorrect Authorization vulnerability
Moderate
CVE-2024-28148
was published
for
apache-superset
(pip)
May 7, 2024
Avast Premium Security Sandbox Protection Incorrect Authorization Privilege Escalation...
Moderate
Unreviewed
CVE-2023-42124
was published
May 3, 2024
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16...
Moderate
Unreviewed
CVE-2024-4006
was published
Apr 25, 2024
Incorrect Authorization vulnerability in Supsystic Data Tables Generator.This issue affects Data...
Moderate
Unreviewed
CVE-2023-25043
was published
Apr 17, 2024
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component:...
Moderate
Unreviewed
CVE-2024-21120
was published
Apr 17, 2024
Argo CD's API server does not enforce project sourceNamespaces
Moderate
CVE-2024-31990
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Apr 15, 2024
Apache Pulsar: Improper Authorization For Namespace and Topic Management Endpoints
Moderate
CVE-2024-29834
was published
for
org.apache.pulsar:pulsar-broker
(Maven)
Apr 2, 2024
In JetBrains TeamCity before 2024.03 authenticated users without administrative permissions could...
Moderate
Unreviewed
CVE-2024-31134
was published
Mar 28, 2024
Elasticsearch Incorrect Authorization vulnerability
Moderate
CVE-2024-23451
was published
for
org.elasticsearch:elasticsearch
(Maven)
Mar 27, 2024
Improper authorization in the report management and creation module of BMC Control-M branches 9.0...
Moderate
Unreviewed
CVE-2024-1604
was published
Mar 18, 2024
vantage6's CORS settings overly permissive
Moderate
CVE-2024-23823
was published
for
vantage6
(pip)
Mar 15, 2024
Apache Pulsar: Improper Authorization For Topic-Level Policy Management
Moderate
CVE-2024-28098
was published
for
org.apache.pulsar:pulsar-broker
(Maven)
Mar 12, 2024
A vulnerability has been identified in Siveillance Control (All versions >= V2.8 < V3.1.1). The...
Moderate
Unreviewed
CVE-2023-45793
was published
Mar 12, 2024
SAP Fiori Front End Server - version 605, allows altering of approver details on the read-only...
Moderate
Unreviewed
CVE-2024-22133
was published
Mar 12, 2024
In JetBrains YouTrack before 2024.1.25893 user without appropriate permissions could restore...
Moderate
Unreviewed
CVE-2024-28229
was published
Mar 7, 2024
A privilege escalation vulnerability was discovered in GitLab affecting versions 16.8 prior to 16...
Moderate
Unreviewed
CVE-2024-1299
was published
Mar 7, 2024
In JetBrains TeamCity before 2023.11.4 presigned URL generation requests in S3 Artifact Storage...
Moderate
Unreviewed
CVE-2024-28174
was published
Mar 6, 2024
1Panel open source panel project has an unauthorized vulnerability.
Moderate
CVE-2024-27288
was published
for
github.com/1Panel-dev/1Panel
(Go)
Mar 6, 2024
ProTip!
Advisories are also available from the
GraphQL API