GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,055
Erlang
29
GitHub Actions
19
Go
1,889
Maven
5,000+
npm
3,605
NuGet
638
pip
3,208
Pub
10
RubyGems
852
Rust
816
Swift
35
Unreviewed advisories
All unreviewed
5,000+
956 advisories
Filter by severity
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote...
Moderate
Unreviewed
CVE-2024-31403
was published
Jun 11, 2024
Dell Client Platform contains an incorrect authorization vulnerability. An attacker with physical...
Moderate
Unreviewed
CVE-2024-0160
was published
Jun 12, 2024
Magento Open Source Incorrect Authorization vulnerability
Moderate
CVE-2024-34106
was published
for
magento/community-edition
(Composer)
Jun 13, 2024
Acrobat Mobile Sign Android versions 24.4.2.33155 and earlier are affected by an Incorrect...
Moderate
Unreviewed
CVE-2024-34130
was published
Jun 13, 2024
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to unauthorized loss...
Moderate
Unreviewed
CVE-2024-5860
was published
Jun 18, 2024
SFTPGo has insufficient access control for password reset
Moderate
CVE-2024-37897
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jun 20, 2024
The License Manager for WooCommerce plugin for WordPress is vulnerable to unauthorized access of...
Moderate
Unreviewed
CVE-2024-1639
was published
Jun 21, 2024
IBM Security Access Manager Docker 10.0.0.0 through 10.0.7.1 could disclose sensitive information...
Moderate
Unreviewed
CVE-2023-38368
was published
Jun 27, 2024
aimeos/ai-admin-jsonadm improper access control vulnerability allows editors to remove required records
Moderate
CVE-2024-39322
was published
for
aimeos/ai-admin-jsonadm
(Composer)
Jul 2, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1)....
Moderate
Unreviewed
CVE-2024-39871
was published
Jul 9, 2024
Red-DiscordBot vulnerable to Incorrect Authorization in commands API
Moderate
CVE-2024-39905
was published
for
Red-DiscordBot
(pip)
Jul 11, 2024
NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects
Moderate
CVE-2022-29946
was published
for
github.com/nats-io/nats-server
(Go)
Jul 11, 2024
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed...
Moderate
Unreviewed
CVE-2024-5817
was published
Jul 17, 2024
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed...
Moderate
Unreviewed
CVE-2024-5816
was published
Jul 17, 2024
Silverstripe Reports are still accessible even when `canView()` returns false
Moderate
CVE-2024-29885
was published
for
silverstripe/reports
(Composer)
Jul 17, 2024
matrix-sdk-crypto's `UserIdentity::is_verified` not checking verification status of own user identity while performing the check
Moderate
CVE-2024-40648
was published
for
matrix-sdk-crypto
(Rust)
Jul 18, 2024
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via...
Moderate
Unreviewed
CVE-2024-4447
was published
Jul 26, 2024
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
Moderate
Unreviewed
CVE-2024-6358
was published
Aug 6, 2024
A vulnerability has been identified in SINEC NMS (All versions < V3.0). The affected application...
Moderate
Unreviewed
CVE-2024-41941
was published
Aug 13, 2024
Microcks's POST /api/import and POST /api/export endpoints allow non-administrator access
Moderate
CVE-2024-44076
was published
for
io.github.microcks:microcks-app
(Maven)
Aug 19, 2024
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server, allowing an...
Moderate
Unreviewed
CVE-2024-7711
was published
Aug 20, 2024
An Incorrect Authorization vulnerability was identified in GitHub Enterprise Server that allowed...
Moderate
Unreviewed
CVE-2024-6337
was published
Aug 20, 2024
Logsign Unified SecOps Platform Incorrect Authorization Authentication Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2024-7604
was published
Aug 21, 2024
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to...
Moderate
Unreviewed
CVE-2024-7836
was published
Aug 22, 2024
An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus,...
Moderate
Unreviewed
CVE-2024-38869
was published
Aug 23, 2024
ProTip!
Advisories are also available from the
GraphQL API