GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,023
Erlang
29
GitHub Actions
16
Go
1,830
Maven
5,000+
npm
3,573
NuGet
632
pip
3,156
Pub
10
RubyGems
847
Rust
796
Swift
34
Unreviewed advisories
All unreviewed
5,000+
1,522 advisories
Filter by severity
CloudStack account-users by default use username and password based authentication for API and UI...
High
Unreviewed
CVE-2024-42062
was published
Aug 7, 2024
mod_css_styles in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a insufficiently filters...
High
Unreviewed
CVE-2024-42010
was published
Aug 5, 2024
stitionai/devika main branch as of commit cdfb782b0e634b773b10963c8034dc9207ba1f9f is vulnerable...
High
Unreviewed
CVE-2024-6331
was published
Aug 4, 2024
openstack-heat may disclose sensitive information
High
CVE-2024-7319
was published
for
openstack-heat
(pip)
Aug 2, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr...
High
Unreviewed
CVE-2024-38761
was published
Aug 2, 2024
Priority
PRI WEB Portal Add-On for Priority ERP on prem
- CWE-200: Exposure of Sensitive...
High
Unreviewed
CVE-2024-41696
was published
Jul 30, 2024
Apache Pinot: Unauthorized endpoint exposed sensitive information
High
CVE-2024-39676
was published
for
org.apache.pinot:pinot-controller
(Maven)
Jul 24, 2024
A validated user not explicitly authorized to have access to certain sensitive information could...
High
Unreviewed
CVE-2023-40159
was published
Jul 18, 2024
Gotenberg provides a developer-friendly API to interact with powerful tools like Chromium and...
High
Unreviewed
CVE-2024-40639
was published
Jul 17, 2024
Sylius has a security vulnerability via adjustments API endpoint
High
CVE-2024-40633
was published
for
sylius/sylius
(Composer)
Jul 17, 2024
Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite ...
High
Unreviewed
CVE-2024-21152
was published
Jul 17, 2024
Sensitive information disclosure due to excessive privileges assigned to Acronis Agent. The...
High
Unreviewed
CVE-2022-45449
was published
Jul 16, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Automattic Newspack...
High
Unreviewed
CVE-2024-37115
was published
Jul 10, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Membership Software...
High
Unreviewed
CVE-2024-37110
was published
Jul 10, 2024
An unauthenticated remote attacker can read out sensitive device information through a...
High
Unreviewed
CVE-2024-6421
was published
Jul 10, 2024
Exposure of Sensitive Information to an Unauthorized Actor in Samsung Galaxy SmartTag2 prior to 0...
High
Unreviewed
CVE-2024-32670
was published
Jul 10, 2024
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801,...
High
Unreviewed
CVE-2023-52237
was published
Jul 9, 2024
Directus Allows Single Sign-On User Enumeration
High
CVE-2024-39896
was published
for
directus
(npm)
Jul 8, 2024
An issue was discovered in the CheckUser extension for MediaWiki through 1.42.1. It can expose...
High
Unreviewed
CVE-2024-40597
was published
Jul 7, 2024
Best House Rental Management System v1.0 was discovered to contain an arbitrary file read...
High
Unreviewed
CVE-2024-39210
was published
Jul 5, 2024
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the ...
High
Unreviewed
CVE-2024-6506
was published
Jul 4, 2024
Information exposure vulnerability in MESbook 20221021.03 version, the exploitation of which...
High
Unreviewed
CVE-2024-6426
was published
Jul 3, 2024
In WhatsUp Gold versions released before 2023.1.3, a vulnerability exists in the TestController...
High
Unreviewed
CVE-2024-5010
was published
Jun 25, 2024
ProTip!
Advisories are also available from the
GraphQL API