GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,974
Erlang
29
GitHub Actions
16
Go
1,762
Maven
4,984
npm
3,523
NuGet
611
pip
3,098
Pub
10
RubyGems
834
Rust
784
Swift
34
Unreviewed advisories
All unreviewed
5,000+
974 advisories
Filter by severity
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of...
Moderate
Unreviewed
CVE-2024-21597
was published
Jan 12, 2024
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading...
Moderate
Unreviewed
CVE-2024-0443
was published
Jan 12, 2024
Windows CoreMessaging Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-20694
was published
Jan 9, 2024
Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-20692
was published
Jan 9, 2024
Duplicate Advisory: httparty has multipart/form-data request tampering vulnerability
Moderate
GHSA-g47j-3m2m-74qv
was published
for
httparty
(RubyGems)
Jan 4, 2024
•
withdrawn
Apache Airflow vulnerable to Exposure of Resource to Wrong Sphere
Moderate
CVE-2023-48291
was published
for
apache-airflow
(pip)
Dec 21, 2023
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x...
Moderate
Unreviewed
CVE-2023-41120
was published
Dec 12, 2023
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly...
High
Unreviewed
CVE-2023-39171
was published
Dec 7, 2023
In telephony service, there is a possible missing permission check. This could lead to remote...
High
Unreviewed
CVE-2023-42716
was published
Dec 4, 2023
In telephony service, there is a possible missing permission check. This could lead to remote...
High
Unreviewed
CVE-2023-42717
was published
Dec 4, 2023
In telephony service, there is a possible missing permission check. This could lead to local...
Moderate
Unreviewed
CVE-2023-42715
was published
Dec 4, 2023
In dialer, there is a possible way to write permission usage records of an app due to a missing...
Moderate
Unreviewed
CVE-2023-42718
was published
Dec 4, 2023
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Pandora FMS on all...
Moderate
Unreviewed
CVE-2023-41786
was published
Nov 23, 2023
PowerShell Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2023-36013
was published
Nov 20, 2023
Open Management Infrastructure Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2023-36043
was published
Nov 14, 2023
Use of implicit intent for sensitive communication vulnerability in startNameValidationActivity...
Moderate
Unreviewed
CVE-2023-42549
was published
Nov 13, 2023
Use of implicit intent for sensitive communication vulnerability in startEmailValidationActivity...
Moderate
Unreviewed
CVE-2023-42547
was published
Nov 13, 2023
Use of implicit intent for sensitive communication vulnerability in...
Moderate
Unreviewed
CVE-2023-42546
was published
Nov 13, 2023
Use of implicit intent for sensitive communication vulnerability in startTncActivity in Samsung...
Moderate
Unreviewed
CVE-2023-42551
was published
Nov 13, 2023
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Moderate
CVE-2023-5545
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
Moodle Improper Access Control vulnerability
Moderate
CVE-2023-5542
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
A flaw was found In 3Scale Admin Portal. If a user logs out from the personal tokens page and...
Moderate
Unreviewed
CVE-2023-4910
was published
Nov 6, 2023
A vulnerability has been identified in PT-G503 Series versions prior to v5.2, where the session...
Low
Unreviewed
CVE-2023-4217
was published
Nov 2, 2023
A vulnerability was found in insights-client. This security issue occurs because of insecure file...
High
Unreviewed
CVE-2023-3972
was published
Nov 1, 2023
Authenticated clients can read arbitrary files on the MAIN Computer
system using the remote...
Low
Unreviewed
CVE-2023-2622
was published
Nov 1, 2023
ProTip!
Advisories are also available from the
GraphQL API