GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
285 advisories
Filter by severity
A vulnerability was found in Little Apps Little Software Stats. It has been declared as critical....
Critical
Unreviewed
CVE-2015-10057
was published
Jan 16, 2023
Answer contains Improper Access Control vulnerability
Critical
CVE-2023-0744
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the...
Critical
Unreviewed
CVE-2023-22807
was published
Feb 15, 2023
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical...
Critical
Unreviewed
CVE-2023-0963
was published
Feb 22, 2023
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author
Critical
CVE-2023-26474
was published
for
org.xwiki.platform:xwiki-platform-legacy-oldcore
(Maven)
Mar 3, 2023
XWiki Platform users may execute anything with superadmin right through comments and async macro
Critical
CVE-2023-26471
was published
for
org.xwiki.platform:xwiki-platform-rendering-async-macro
(Maven)
Mar 3, 2023
A vulnerability was found in SourceCodester Online Food Ordering System 2.0 and classified as...
Critical
Unreviewed
CVE-2023-1432
was published
Mar 16, 2023
Omron CJ1M unit v4.0 and prior has improper access controls on the memory region where the UM...
Critical
Unreviewed
CVE-2023-0811
was published
Mar 16, 2023
A vulnerability was found in SourceCodester E-Commerce System 1.0. It has been rated as critical....
Critical
Unreviewed
CVE-2023-1557
was published
Mar 22, 2023
Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can...
Critical
Unreviewed
CVE-2023-28808
was published
Apr 11, 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of...
Critical
Unreviewed
CVE-2023-27350
was published
Apr 20, 2023
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
Critical
CVE-2023-29526
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 20, 2023
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and...
Critical
Unreviewed
CVE-2023-31241
was published
May 22, 2023
The Pinterest Automatic plugin for WordPress is vulnerable to authorization bypass due to missing...
Critical
Unreviewed
CVE-2021-4380
was published
Jun 7, 2023
A privilege escalation allowing remote code execution was discovered in the orchestration service.
Critical
Unreviewed
CVE-2023-2530
was published
Jun 7, 2023
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and...
Critical
Unreviewed
CVE-2023-1834
was published
Jul 6, 2023
?Delta Electronics InfraSuite Device Master versions prior to 1.0.7 contain improper access...
Critical
Unreviewed
CVE-2023-30765
was published
Jul 10, 2023
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller...
Critical
Unreviewed
CVE-2023-24489
was published
Jul 11, 2023
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device...
Critical
Unreviewed
CVE-2023-29130
was published
Jul 11, 2023
Access Control Bypass in Spring Security
Critical
CVE-2023-34034
was published
for
org.springframework.security:spring-security-config
(Maven)
Jul 19, 2023
SAP PowerDesigner - version 16.7, has improper access control which might allow an...
Critical
Unreviewed
CVE-2023-37483
was published
Aug 8, 2023
Improper access control in the Intel(R) Ethernet Controller RDMA driver for linux before version...
Critical
Unreviewed
CVE-2023-25775
was published
Aug 11, 2023
XWiki Platform's Groovy jobs check the wrong author, allowing remote code execution
Critical
CVE-2023-40573
was published
for
com.xpn.xwiki.platform.plugins:xwiki-plugin-scheduler
(Maven)
Aug 23, 2023
Account TakeOver Due to Improper Handling of JWT Tokens in usememos/memos
Critical
CVE-2023-4696
was published
for
github.com/usememos/memos
(Go)
Sep 1, 2023
An authentication bypass vulnerability exists in the OAS Engine functionality of Open Automation...
Critical
Unreviewed
CVE-2023-31242
was published
Sep 5, 2023
ProTip!
Advisories are also available from the
GraphQL API