GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,076
Erlang
29
GitHub Actions
19
Go
1,895
Maven
5,000+
npm
3,630
NuGet
638
pip
3,244
Pub
10
RubyGems
862
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
170 advisories
Filter by severity
An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiOS version 7...
High
Unreviewed
CVE-2024-23112
was published
Mar 12, 2024
A vulnerability, which was classified as critical, has been found in SourceCodester Employee Task...
High
Unreviewed
CVE-2024-2575
was published
Mar 18, 2024
A vulnerability classified as critical was found in SourceCodester Employee Task Management...
High
Unreviewed
CVE-2024-2574
was published
Mar 18, 2024
A vulnerability, which was classified as critical, was found in SourceCodester Employee Task...
High
Unreviewed
CVE-2024-2576
was published
Mar 18, 2024
A vulnerability has been found in SourceCodester Employee Task Management System 1.0 and...
High
Unreviewed
CVE-2024-2577
was published
Mar 18, 2024
OneUptime Vulnerable to a Privilege Escalation via Local Storage Key Manipulation
High
CVE-2024-29194
was published
for
@oneuptime/common-server
(npm)
Mar 25, 2024
OpenZFS through 2.1.13 and 2.2.x through 2.2.1, in certain scenarios involving applications that...
High
Unreviewed
CVE-2023-49298
was published
Nov 24, 2023
Bludit prior to 3.9.1 allows a non-privileged user to change the password of any account,...
High
Unreviewed
CVE-2019-12742
was published
May 24, 2022
An authorization bypass vulnerability in pinboard updates in ThoughtSpot 4.4.1 through 5.1.1 ...
High
Unreviewed
CVE-2019-12782
was published
May 24, 2022
In WESEEK GROWI before 3.5.0, the site-wide basic authentication can be bypassed by adding a URL...
High
Unreviewed
CVE-2019-13337
was published
May 24, 2022
The Recruitment module in Humanica Humatrix 7 1.0.0.681 and 1.0.0.203 allows remote attackers to...
High
Unreviewed
CVE-2019-14932
was published
May 24, 2022
An issue was discovered in the Voyager package through 1.2.7 for Laravel. An attacker with admin...
High
Unreviewed
CVE-2019-17050
was published
May 24, 2022
An issue was discovered in GitLab Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11...
High
Unreviewed
CVE-2018-17455
was published
Apr 16, 2023
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before...
High
Unreviewed
CVE-2018-17449
was published
Apr 16, 2023
The RegistrationMagic plugin for WordPress is vulnerable to Insecure Direct Object References in...
High
Unreviewed
CVE-2023-2548
was published
May 16, 2023
Authorization Bypass Through User-Controlled Key vulnerability in Finex Media Competition...
High
Unreviewed
CVE-2023-2702
was published
May 23, 2023
Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo...
High
Unreviewed
CVE-2023-2065
was published
May 24, 2023
Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows...
High
Unreviewed
CVE-2023-2883
was published
May 25, 2023
Incorrect Authorization vulnerability in Mobatime mobile application AMXGT100 allows a low...
High
Unreviewed
CVE-2023-3066
was published
Jun 5, 2023
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid...
High
Unreviewed
CVE-2021-33223
was published
Jun 7, 2023
Unauth. IDOR vulnerability leading to PII Disclosure in WooCommerce Stripe Payment Gateway plugin...
High
Unreviewed
CVE-2023-34000
was published
Jun 14, 2023
Authorization Bypass Through User-Controlled Key vulnerability in JS Help Desk js-support-ticket...
High
Unreviewed
CVE-2023-23679
was published
Jun 23, 2023
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object...
High
Unreviewed
CVE-2023-3063
was published
Jun 30, 2023
The Tutor LMS WordPress plugin before 2.2.1 does not implement adequate permission checks for...
High
Unreviewed
CVE-2023-3133
was published
Jul 4, 2023
Insecure Direct Object Reference vulnerability in WHMCS module SolusVM 1 4.1.2 allows an attacker...
High
Unreviewed
CVE-2022-42175
was published
Jul 5, 2023
ProTip!
Advisories are also available from the
GraphQL API