GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,133
Erlang
29
GitHub Actions
19
Go
1,940
Maven
5,000+
npm
3,678
NuGet
645
pip
3,295
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,137 advisories
Filter by severity
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-9082
was published
Sep 22, 2024
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate...
Moderate
Unreviewed
CVE-2024-47160
was published
Sep 19, 2024
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore...
Moderate
Unreviewed
CVE-2024-47159
was published
Sep 19, 2024
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org...
Critical
Unreviewed
CVE-2024-46918
was published
Sep 16, 2024
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5...
Moderate
Unreviewed
CVE-2024-2743
was published
Sep 12, 2024
A vulnerability in the GlobalProtect portal in Palo Alto Networks PAN-OS software enables a...
Moderate
Unreviewed
CVE-2024-8691
was published
Sep 11, 2024
An access control vulnerability was discovered in the Reports section due to a specific access...
Moderate
Unreviewed
CVE-2024-4465
was published
Sep 11, 2024
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization...
Moderate
Unreviewed
CVE-2024-42423
was published
Sep 10, 2024
SAP NetWeaver Application Server for ABAP and ABAP Platform allow users with high privileges to...
Low
Unreviewed
CVE-2024-44114
was published
Sep 10, 2024
This vulnerability exists in TechExcel Back Office Software versions prior to 1.0.0 due to...
High
Unreviewed
CVE-2024-8601
was published
Sep 9, 2024
Improper authorization in One UI Home prior to SMR Sep-2024 Release 1 allows physical attackers...
Moderate
Unreviewed
CVE-2024-34642
was published
Sep 4, 2024
Incorrect authorization in CocktailbarService prior to SMR Sep-2024 Release 1 allows local...
Moderate
Unreviewed
CVE-2024-34650
was published
Sep 4, 2024
Incorrect authorization in kperfmon prior to SMR Sep-2024 Release 1 allows local attackers to...
Moderate
Unreviewed
CVE-2024-34652
was published
Sep 4, 2024
Improper authorization in My Files prior to SMR Sep-2024 Release 1 allows local attackers to...
Moderate
Unreviewed
CVE-2024-34651
was published
Sep 4, 2024
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to...
High
Unreviewed
CVE-2024-45588
was published
Sep 3, 2024
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to...
High
Unreviewed
CVE-2024-45587
was published
Sep 3, 2024
This vulnerability exists due to improper access controls on APIs in the Authentication module of...
High
Unreviewed
CVE-2024-45586
was published
Sep 3, 2024
In MISP through 2.4.196, app/Controller/BookmarksController.php does not properly restrict access...
Critical
Unreviewed
CVE-2024-45509
was published
Sep 2, 2024
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while...
High
Unreviewed
CVE-2024-38868
was published
Aug 30, 2024
Incorrect Authorization vulnerability in Yassine Idrissi Maintenance & Coming Soon Redirect...
Low
Unreviewed
CVE-2024-43944
was published
Aug 29, 2024
Incorrect Authorization vulnerability in Themeum Droip allows Accessing Functionality Not...
Moderate
Unreviewed
CVE-2024-43954
was published
Aug 29, 2024
Kirby has insufficient permission checks in the language settings
High
CVE-2024-41964
was published
for
getkirby/cms
(Composer)
Aug 29, 2024
AWS CDK RestApi not generating authorizationScope correctly in resultant CFN template
Moderate
CVE-2024-45037
was published
for
aws-cdk
(npm)
Aug 27, 2024
Logitech Options+ on MacOS prior 1.72 allows a local attacker to inject dynamic library within...
Low
Unreviewed
CVE-2024-8011
was published
Aug 25, 2024
An Stored Cross-site Scripting vulnerability affects Zohocorp ManageEngine ServiceDesk Plus,...
Moderate
Unreviewed
CVE-2024-38869
was published
Aug 23, 2024
ProTip!
Advisories are also available from the
GraphQL API