GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,083
Erlang
29
GitHub Actions
19
Go
1,909
Maven
5,000+
npm
3,643
NuGet
638
pip
3,260
Pub
10
RubyGems
869
Rust
820
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,055 advisories
Filter by severity
Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access
Moderate
CVE-2024-44076
was published
for
io.github.microcks:microcks-app
(Maven)
Aug 19, 2024
Logical vulnerability in the mobile application (com.transsion.carlcare) may lead to user...
High
Unreviewed
CVE-2024-7697
was published
Aug 12, 2024
Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2024-7604
was published
Aug 21, 2024
Capsule tenant owner with "patch namespace" permission can hijack system namespaces
High
CVE-2024-39690
was published
for
github.com/projectcapsule/capsule
(Go)
Aug 20, 2024
Apache Archiva Incorrect Authorization vulnerability
High
CVE-2024-27138
was published
for
org.apache.archiva:archiva
(Maven)
Mar 1, 2024
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to...
Moderate
Unreviewed
CVE-2024-7836
was published
Aug 22, 2024
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 5.15.2 allows a remote...
Moderate
Unreviewed
CVE-2024-31402
was published
Jun 11, 2024
Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy...
High
Unreviewed
CVE-2024-7266
was published
Aug 7, 2024
Incorrect User Management vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy...
High
Unreviewed
CVE-2024-7265
was published
Aug 7, 2024
GoAuthentik vulnerable to Insufficient Authorization for several API endpoints
High
CVE-2024-42490
was published
for
goauthentik.io
(Go)
Aug 22, 2024
AWS CDK RestApi not generating authorizationScope correctly in resultant CFN template
Moderate
CVE-2024-45037
was published
for
aws-cdk
(npm)
Aug 27, 2024
Incorrect Authorization vulnerability in Yassine Idrissi Maintenance & Coming Soon Redirect...
Low
Unreviewed
CVE-2024-43944
was published
Aug 29, 2024
Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not...
Moderate
Unreviewed
CVE-2024-43954
was published
Aug 29, 2024
Kirby has insufficient permission checks in the language settings
High
CVE-2024-41964
was published
for
getkirby/cms
(Composer)
Aug 29, 2024
An improper access control vulnerability exists in GitLab Remote Development affecting all...
Moderate
Unreviewed
CVE-2023-6955
was published
Jan 12, 2024
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11...
Low
Unreviewed
CVE-2024-4011
was published
Jun 27, 2024
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to...
High
Unreviewed
CVE-2024-6323
was published
Jun 27, 2024
An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus,...
Moderate
Unreviewed
CVE-2024-38869
was published
Aug 23, 2024
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while...
High
Unreviewed
CVE-2024-38868
was published
Aug 30, 2024
lunary-ai/lunary allows users unauthorized access to projects
Critical
CVE-2024-4146
was published
for
lunary
(npm)
Jun 8, 2024
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to...
High
Unreviewed
CVE-2024-45588
was published
Sep 3, 2024
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to...
High
Unreviewed
CVE-2024-45587
was published
Sep 3, 2024
This vulnerability exists due to improper access controls on APIs in the Authentication module of...
High
Unreviewed
CVE-2024-45586
was published
Sep 3, 2024
AdTran SRG 834-5 HDC17600021F1 devices (with SmartOS 11.1.1.1 and fixed in Version 12.1.3.1) have...
High
Unreviewed
CVE-2024-31970
was published
Jul 24, 2024
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access...
Critical
Unreviewed
CVE-2024-45509
was published
Sep 2, 2024
ProTip!
Advisories are also available from the
GraphQL API