GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,703
NuGet
661
pip
3,329
Pub
11
RubyGems
884
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
605 advisories
Filter by severity
Authorization Bypass Through User-Controlled Key vulnerability in WP Job Portal.This issue...
Moderate
Unreviewed
CVE-2024-43266
was published
Aug 19, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Masteriyo Masteriyo - LMS.This...
Moderate
Unreviewed
CVE-2024-43239
was published
Aug 19, 2024
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product...
High
Unreviewed
CVE-2024-42464
was published
Aug 16, 2024
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product...
High
Unreviewed
CVE-2024-42463
was published
Aug 16, 2024
The Custom Field For WP Job Manager plugin for WordPress is vulnerable to Insecure Direct Object...
Moderate
Unreviewed
CVE-2023-7049
was published
Aug 16, 2024
Insecure Permissions vulnerability in Friendica v.2023.12 allows a remote attacker to obtain...
Critical
Unreviewed
CVE-2024-27730
was published
Aug 15, 2024
Improper access control in Directus
Moderate
CVE-2024-6534
was published
for
directus
(npm)
Aug 15, 2024
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access...
Moderate
Unreviewed
CVE-2024-21981
was published
Aug 13, 2024
Authorization Bypass Through User-Controlled Key vulnerability in ThimPress LearnPress allows...
Moderate
Unreviewed
CVE-2024-39642
was published
Aug 13, 2024
A vulnerability, which was classified as problematic, has been found in projectsend up to r1605....
Moderate
Unreviewed
CVE-2024-7658
was published
Aug 12, 2024
A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior...
Moderate
Unreviewed
CVE-2024-3035
was published
Aug 8, 2024
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
Moderate
Unreviewed
CVE-2024-6357
was published
Aug 6, 2024
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic....
Moderate
Unreviewed
CVE-2024-7438
was published
Aug 3, 2024
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4....
Moderate
Unreviewed
CVE-2024-7437
was published
Aug 3, 2024
An issue was discovered in litestream v0.3.13. The usage of the ssh.InsecureIgnoreHostKey()...
Moderate
Unreviewed
CVE-2024-41254
was published
Jul 31, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Academy LMS.This issue affects...
Moderate
Unreviewed
CVE-2024-38701
was published
Jul 22, 2024
On versions before 2.1.4, after a regular user successfully logs in, they can manually make a...
Moderate
Unreviewed
CVE-2024-34457
was published
Jul 22, 2024
Withdrawn: SFTPGo's JWT implmentation lacks certain security measures
Moderate
CVE-2024-40430
was published
for
github.com/drakkan/sftpgo/v2
(Go)
Jul 22, 2024
•
withdrawn
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-5977
was published
Jul 19, 2024
Authorization Bypass Through User-Controlled Key vulnerability in PruvaSoft Informatics Apinizer...
Critical
Unreviewed
CVE-2024-5619
was published
Jul 18, 2024
The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
Moderate
CVE-2024-39900
was published
for
org.opensearch.plugin:opensearch-reports-scheduler
(Maven)
Jul 18, 2024
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the...
Moderate
Unreviewed
CVE-2024-38446
was published
Jul 17, 2024
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request...
High
Unreviewed
CVE-2024-38447
was published
Jul 17, 2024
Sylius has a security vulnerability via adjustments API endpoint
High
CVE-2024-40633
was published
for
sylius/sylius
(Composer)
Jul 17, 2024
OpenSearch Observability does not properly restrict access to private tenant resources
Moderate
CVE-2024-39901
was published
for
org.opensearch.plugin:opensearch-observability
(Maven)
Jul 10, 2024
ProTip!
Advisories are also available from the
GraphQL API