GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,737
Maven
5,000+
npm
4,337
NuGet
764
pip
4,112
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
136 advisories
Filter by severity
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers...
High
Unreviewed
CVE-2024-20320
was published
Mar 13, 2024
This issue was addressed by removing the vulnerable code. This issue is fixed in tvOS 17.4, iOS...
High
Unreviewed
CVE-2024-23288
was published
Mar 8, 2024
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with...
High
Unreviewed
CVE-2023-50437
was published
Feb 29, 2024
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL...
High
Unreviewed
CVE-2023-40109
was published
Feb 16, 2024
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom...
High
Unreviewed
CVE-2023-49647
was published
Jan 13, 2024
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The...
High
Unreviewed
CVE-2023-5913
was published
Nov 8, 2023
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and...
High
Unreviewed
CVE-2023-4153
was published
Sep 13, 2023
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to...
High
Unreviewed
CVE-2020-10129
was published
Sep 6, 2023
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into...
High
Unreviewed
CVE-2023-21269
was published
Aug 14, 2023
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to...
High
Unreviewed
CVE-2023-30691
was published
Aug 10, 2023
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows...
High
Unreviewed
CVE-2023-30680
was published
Aug 10, 2023
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain...
High
Unreviewed
CVE-2023-39173
was published
Jul 25, 2023
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to...
High
Unreviewed
CVE-2023-28956
was published
Jun 22, 2023
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to,...
High
Unreviewed
CVE-2023-1874
was published
Apr 12, 2023
In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset...
High
Unreviewed
CVE-2023-20957
was published
Mar 24, 2023
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this...
High
Unreviewed
CVE-2022-4281
was published
Dec 5, 2022
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has...
High
Unreviewed
CVE-2022-3549
was published
Oct 17, 2022
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified...
High
Unreviewed
CVE-2022-3496
was published
Oct 14, 2022
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance...
High
Unreviewed
CVE-2022-3436
was published
Oct 10, 2022
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
High
Unreviewed
CVE-2022-2626
was published
Aug 6, 2022
The authentication mechanism used by poll workers to administer voting using the tested version...
High
Unreviewed
CVE-2022-1746
was published
Jun 25, 2022
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11...
High
Unreviewed
CVE-2021-20264
was published
May 24, 2022
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an...
High
Unreviewed
CVE-2021-1594
was published
May 24, 2022
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An...
High
Unreviewed
CVE-2020-10695
was published
May 24, 2022
An insecure modification vulnerability in the /etc/passwd file was found in the operator...
High
Unreviewed
CVE-2019-19353
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API