GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
106 advisories
Filter by severity
Improper Handling of Insufficient Permissions or Privileges vulnerability in SemChameleonHelper...
Low
Unreviewed
CVE-2023-21424
was published
Feb 9, 2023
Improper authorization in UPI payment in Samsung Pass prior to version 4.0.04.10 allows physical...
Low
Unreviewed
CVE-2022-36876
was published
Sep 10, 2022
Improper Authorization vulnerability in Video Editor prior to SMR Sep-2022 Release 1 allows local...
Low
Unreviewed
CVE-2022-36852
was published
Sep 10, 2022
Improper Authorization vulnerability in Photo Editor prior to SMR Sep-2022 Release 1 allows...
Low
Unreviewed
CVE-2022-36857
was published
Sep 10, 2022
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to...
Low
Unreviewed
CVE-2022-22272
was published
Jan 11, 2022
Improper access control vulnerability in Samsung SearchWidget prior to versions 2.3.00.6 in China...
Low
Unreviewed
CVE-2022-24923
was published
Feb 12, 2022
Improper access control vulnerability in Samsung Flow prior to version 4.8.06.5 allows attacker...
Low
Unreviewed
CVE-2022-28775
was published
Apr 12, 2022
Improper access control vulnerability in Samsung Security Supporter prior to version 1.2.40.0...
Low
Unreviewed
CVE-2022-28778
was published
Apr 12, 2022
Improper access control vulnerability in Samsung Members prior to version 13.6.08.5 allows local...
Low
Unreviewed
CVE-2022-28777
was published
Apr 12, 2022
Improper authorization in isemtelephony prior to SMR Jul-2022 Release 1 allows attacker to obtain...
Low
Unreviewed
CVE-2022-30757
was published
Jul 13, 2022
Information exposure in Calendar prior to version 12.3.05.10000 allows attacker to access...
Low
Unreviewed
CVE-2022-33705
was published
Jul 13, 2022
Byobu user preference to prevent private discussions being started are not respected
Low
CVE-2022-35921
was published
for
fof/byobu
(Composer)
Aug 6, 2022
Insufficient user authorization in Moodle
Low
CVE-2022-0333
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource
Low
CVE-2023-3485
was published
for
go.temporal.io/server
(Go)
Jun 30, 2023
Mattermost Incorrect Authorization vulnerability
Low
CVE-2023-5159
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Sep 29, 2023
Mattermost Incorrect Authorization vulnerability
Low
CVE-2023-5193
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Sep 29, 2023
Sensitive information disclosure and manipulation due to improper authorization. The following...
Low
Unreviewed
CVE-2023-44154
was published
Sep 27, 2023
kiwi TCMS has possibility for user to update email address to unverified one
Low
CVE-2023-30544
was published
for
kiwitcms
(pip)
Apr 24, 2023
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed...
Low
Unreviewed
CVE-2023-51380
was published
Dec 21, 2023
A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and...
Low
Unreviewed
CVE-2022-3582
was published
Oct 18, 2022
Incorrect Authorization in Jenkins Core
Low
CVE-2023-27903
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Information leak in Gerrit
Low
CVE-2020-8920
was published
for
com.google.gerrit:gerrit-plugin-api
(Maven)
May 24, 2022
Backoffice User can bypass "Publish" restriction
Low
CVE-2023-48227
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
Improper authorization verification vulnerability in Samsung Internet prior to version 24.0...
Low
Unreviewed
CVE-2024-20828
was published
Feb 6, 2024
Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team...
Low
Unreviewed
CVE-2023-3584
was published
Jul 17, 2023
ProTip!
Advisories are also available from the
GraphQL API