GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
189 advisories
Filter by severity
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom...
High
Unreviewed
CVE-2023-49647
was published
Jan 13, 2024
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper...
Moderate
Unreviewed
CVE-2023-47140
was published
Jan 8, 2024
The FACSChorus software does not properly assign data access privileges for operating system user...
Low
Unreviewed
CVE-2023-29066
was published
Nov 28, 2023
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The...
High
Unreviewed
CVE-2023-5913
was published
Nov 8, 2023
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
High
CVE-2023-5077
was published
for
github.com/hashicorp/vault
(Go)
Sep 29, 2023
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and...
High
Unreviewed
CVE-2023-4153
was published
Sep 13, 2023
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to...
High
Unreviewed
CVE-2020-10129
was published
Sep 6, 2023
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into...
High
Unreviewed
CVE-2023-21269
was published
Aug 14, 2023
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows...
High
Unreviewed
CVE-2023-30680
was published
Aug 10, 2023
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to...
High
Unreviewed
CVE-2023-30691
was published
Aug 10, 2023
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High
CVE-2023-3518
was published
for
github.com/hashicorp/consul
(Go)
Aug 9, 2023
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain...
High
Unreviewed
CVE-2023-39173
was published
Jul 25, 2023
Nomad Search API Leaks Information About CSI Plugins
Moderate
CVE-2023-3300
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
Nomad ACL Policies without Label are Applied to Unexpected Resources
Moderate
CVE-2023-3072
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to...
High
Unreviewed
CVE-2023-28956
was published
Jun 22, 2023
AWS CDK EKS overly permissive trust policies
Moderate
CVE-2023-35165
was published
for
@aws-cdk/aws-eks
(npm)
Jun 19, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15...
Moderate
Unreviewed
CVE-2023-2485
was published
Jun 7, 2023
Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
High
CVE-2023-2816
was published
for
github.com/hashicorp/consul
(Go)
Jun 3, 2023
This vulnerability exposes a network port in minikube running on macOS with Docker driver that...
Critical
Unreviewed
CVE-2023-1174
was published
May 24, 2023
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to,...
High
Unreviewed
CVE-2023-1874
was published
Apr 12, 2023
text_helpers uses web link to untrusted target with window.opener access
Moderate
CVE-2020-36624
was published
for
text_helpers
(RubyGems)
Dec 22, 2022
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension...
Moderate
Unreviewed
CVE-2022-4613
was published
Dec 19, 2022
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this...
High
Unreviewed
CVE-2022-4281
was published
Dec 5, 2022
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by...
Critical
Unreviewed
CVE-2022-4272
was published
Dec 3, 2022
A vulnerability, which was classified as critical, has been found in SourceCodester Human...
Critical
Unreviewed
CVE-2022-4273
was published
Dec 3, 2022
ProTip!
Advisories are also available from the
GraphQL API