GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
190 advisories
Filter by severity
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4807
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4806
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4810
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to improper access control
Moderate
CVE-2022-4685
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
Sentry vulnerable to invite code reuse via cookie manipulation
Moderate
CVE-2022-23485
was published
for
sentry
(pip)
Dec 12, 2022
Budibase Improper Access Control vulnerability
Moderate
CVE-2022-3225
was published
for
@budibase/bbui
(npm)
Sep 17, 2022
Magento Improper Access Control vulnerability
Moderate
CVE-2022-34259
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
GNU Mailman Postorius Access Control Issues
Moderate
CVE-2021-40347
was published
for
postorius
(pip)
May 24, 2022
JetPack Exposure of Resource to Wrong Sphere
Moderate
CVE-2021-24374
was published
for
automattic/jetpack
(Composer)
May 24, 2022
Magento Improper Access Control
Moderate
CVE-2021-21020
was published
for
magento/community-edition
(Composer)
May 24, 2022
Missing permission check in Jenkins Build Failure Analyzer Plugin
Moderate
CVE-2019-16554
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 24, 2022
Wildfly Authorization Misconfiguration
Moderate
CVE-2019-14838
was published
for
org.wildfly.core:wildfly-host-controller
(Maven)
May 24, 2022
moodle Improper Access Control
Moderate
CVE-2019-10189
was published
for
moodle/moodle
(Composer)
May 24, 2022
Moodle Ability to delete glossary entries that belong to another glossary
Moderate
CVE-2019-10187
was published
for
moodle/moodle
(Composer)
May 24, 2022
moodle Improper Access Control
Moderate
CVE-2019-10188
was published
for
moodle/moodle
(Composer)
May 24, 2022
MediaWiki Incorrect Access Control vulnerability
Moderate
CVE-2019-12469
was published
for
mediawiki/core
(Composer)
May 24, 2022
Wikimedia MediaWik exposed suppressed log in RevisionDelete page
Moderate
CVE-2019-12470
was published
for
mediawiki/core
(Composer)
May 24, 2022
MediaWiki Incorrect Access Control vulnerability
Moderate
CVE-2019-12467
was published
for
mediawiki/core
(Composer)
May 24, 2022
Openstack Octavia Access Control Vulnerability
Moderate
CVE-2019-3895
was published
for
octavia
(pip)
May 24, 2022
Publify has Improper Access Controls
Moderate
CVE-2022-1810
was published
for
publify_core
(RubyGems)
May 24, 2022
Chef Improper Access Control vulnerability
Moderate
CVE-2010-5142
was published
for
chef
(RubyGems)
May 17, 2022
Improper Access Control in JBoss mod_cluster
Moderate
CVE-2012-1154
was published
for
org.jboss.mod_cluster:mod_cluster
(Maven)
May 17, 2022
Symfony Access Control Vulnerability
Moderate
CVE-2012-6432
was published
for
symfony/symfony
(Composer)
May 17, 2022
Drupal improper access restrictions
Moderate
CVE-2012-2153
was published
for
drupal/drupal
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API