GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
190 advisories
Filter by severity
Mattermost does not validate requesting user permissions before updating admin details
Moderate
CVE-2023-4107
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Mattermost fails to check if user is a guest before performing actions on public playbooks
Moderate
CVE-2023-4106
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Easy!Appointments Improper Access Control vulnerability
Moderate
CVE-2023-3700
was published
for
alextselegidis/easyappointments
(Composer)
Jul 17, 2023
PlantUML Improper Access Control vulnerability
Moderate
CVE-2023-3431
was published
for
net.sourceforge.plantuml:plantuml-mit
(Maven)
Jun 27, 2023
Admidio Improper Access Control vulnerability
Moderate
CVE-2023-3304
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
When setting EntityOptions.apiPrefilter to a function, the filter is not applied to API requests for a resource by Id
Moderate
CVE-2023-35167
was published
for
remult
(npm)
Jun 20, 2023
Grafana has Broken Access Control in Alert manager: Viewer can send test alerts
Moderate
CVE-2023-2183
was published
for
github.com/grafana/grafana
(Go)
Jun 12, 2023
Duplicate Advisory: Grafana Improper Access Control vulnerability
Moderate
GHSA-wm7r-3qxj-5xgq
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
•
withdrawn
TeamPass vulnerable to Improper Access Control
Moderate
CVE-2023-3095
was published
for
nilsteampassnet/teampass
(Composer)
Jun 4, 2023
kyverno seccomp control can be circumvented
Moderate
CVE-2023-33191
was published
for
github.com/kyverno/kyverno
(Go)
May 25, 2023
Liferay portal unauthorized access to objects via OAuth 2 scope
Moderate
CVE-2023-33946
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
Liferay portal has unauthorized access to object definition via search
Moderate
CVE-2023-33947
was published
for
com.liferay.portal:release.portal.bom
(Maven)
May 24, 2023
phpMyFAQ Improper Access Control vulnerability
Moderate
CVE-2023-2429
was published
for
thorsten/phpmyfaq
(Composer)
Apr 30, 2023
RosarioSIS improper access control vulnerability
Moderate
CVE-2023-2202
was published
for
francoisjacquet/rosariosis
(Composer)
Apr 21, 2023
xwiki-platform-web-templates allows users to be created even when registration is disabled without validation via template macro
Moderate
CVE-2023-29513
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 20, 2023
PowerJob vulnerable to Incorrect Access Control via the create user/save interface.
Moderate
CVE-2023-29922
was published
for
tech.powerjob:powerjob
(Maven)
Apr 19, 2023
alextselegidis/easyappointments Improper Access Control vulnerability
Moderate
CVE-2023-2104
was published
for
alextselegidis/easyappointments
(Composer)
Apr 15, 2023
thorsten/phpmyfaq vulnerable to improper access control
Moderate
CVE-2023-1883
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Jenkins OctoPerf Load Testing Plugin missing permission check allows for ID enumeration
Moderate
CVE-2023-28673
was published
for
org.jenkinsci.plugins:octoperf
(Maven)
Apr 2, 2023
Jenkins OctoPerf Load Testing Plugin missing permission check allows for unauthorized server connections
Moderate
CVE-2023-28675
was published
for
org.jenkinsci.plugins:octoperf
(Maven)
Apr 2, 2023
directus vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2023-28443
was published
for
directus
(npm)
Mar 23, 2023
Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm
Moderate
CVE-2023-26473
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Mar 3, 2023
Apache Superset has Improper Access Control
Moderate
CVE-2022-45438
was published
for
apache-superset
(pip)
Jan 16, 2023
Keycloak has lack of validation of access token on client registrations endpoint
Moderate
CVE-2023-0091
was published
for
org.keycloak:keycloak-core
(Maven)
Jan 12, 2023
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4806
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
ProTip!
Advisories are also available from the
GraphQL API