GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
999 advisories
Filter by severity
Improper Access Controls allows access to protected views.
High
Unreviewed
CVE-2024-40749
was published
Jan 7, 2025
Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378...
High
Unreviewed
CVE-2023-25174
was published
Jan 7, 2025
OpenShift Hive RCE through AWS/Kubernetes client configuration leads to privilege escalation
High
CVE-2024-25133
was published
for
github.com/openshift/hive
(Go)
Dec 31, 2024
Microsoft Dynamics Business Central Elevation Of Privilege Vulnerability
High
Unreviewed
CVE-2023-38167
was published
Aug 8, 2023
Keycloak's admin API allows low privilege users to use administrative functions
High
CVE-2024-3656
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 11, 2024
Remote Desktop Client Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49105
was published
Dec 12, 2024
Microsoft SharePoint Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-49068
was published
Dec 12, 2024
Microsoft Office Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-43600
was published
Dec 12, 2024
System Center Operations Manager Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-43594
was published
Dec 12, 2024
Dell Power Manager (DPM), versions prior to 3.17, contain an improper access control...
High
Unreviewed
CVE-2024-49600
was published
Dec 9, 2024
Bots using py-cord as Discord API wrapper are vulnerable to shutdowns through remote code execution
High
CVE-2022-36024
was published
for
py-cord
(pip)
Aug 18, 2022
Multiple vulnerabilities in the payload inspection for Ethernet Industrial Protocol (ENIP)...
High
Unreviewed
CVE-2021-34754
was published
May 24, 2022
MoinMoin Access Restrictions Bypassed due to improper ACL enforcement
High
CVE-2008-6603
was published
for
moin
(pip)
May 17, 2022
MoinMoin vulnerable to privilege escalation
High
CVE-2008-1937
was published
for
moin
(pip)
May 1, 2022
QSEE will randomly experience a fatal error during execution due to speculative instruction...
High
Unreviewed
CVE-2016-10408
was published
Nov 26, 2024
BlueZ HID over GATT Profile Improper Access Control Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-8805
was published
Nov 22, 2024
Improper access control vulnerability in Apaczka plugin for PrestaShop allows information...
High
Unreviewed
CVE-2024-2759
was published
Apr 4, 2024
Lunary improper access control vulnerability
High
CVE-2024-6087
was published
for
lunary
(npm)
Sep 13, 2024
Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams
High
CVE-2024-42497
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 22, 2024
Mattermost allows remote actor to create/update/delete posts in arbitrary channels
High
CVE-2024-41144
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 1, 2024
rejetto HFS vulnerable to OS Command Execution by remote authenticated users
High
CVE-2024-39943
was published
for
hfs
(npm)
Jul 5, 2024
Directus incorrectly handles `_in` filter
High
CVE-2024-39701
was published
for
directus
(npm)
Jul 8, 2024
Mattermost fails to authenticate the source of certain types of post actions
High
CVE-2024-2447
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 5, 2024
Mattermost post fetching without auditing in compliance export
High
CVE-2024-1887
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 29, 2024
ZenML Server Remote Privilege Escalation Vulnerability
High
CVE-2024-25723
was published
for
zenml
(pip)
Feb 27, 2024
ProTip!
Advisories are also available from the
GraphQL API