GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,757
NuGet
678
pip
3,444
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
286 advisories
Filter by severity
Zoho ManageEngine Access Manager Plus before 4302, Password Manager Pro before 12007, and PAM360...
Critical
Unreviewed
CVE-2022-29081
was published
Apr 29, 2022
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13281
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows...
Critical
Unreviewed
CVE-2024-13258
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows...
Critical
Unreviewed
CVE-2024-13253
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue...
Critical
Unreviewed
CVE-2024-13278
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue...
Critical
Unreviewed
CVE-2024-13277
was published
Jan 9, 2025
lunary-ai/lunary version 1.0.1 is vulnerable to improper authorization, allowing removed members...
Critical
Unreviewed
CVE-2024-1741
was published
Apr 10, 2024
An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network...
Critical
Unreviewed
CVE-2023-27716
was published
Jun 12, 2023
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
Critical
Unreviewed
CVE-2023-32220
was published
Jun 12, 2023
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0...
Critical
Unreviewed
CVE-2024-45519
was published
Oct 3, 2024
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android...
Critical
Unreviewed
CVE-2023-4617
was published
Dec 19, 2024
Dante 1.4.0 through 1.4.3 (fixed in 1.4.4) has incorrect access control for some sockd.conf...
Critical
Unreviewed
CVE-2024-54662
was published
Dec 17, 2024
A permissions issue was addressed by removing vulnerable code and adding additional checks. This...
Critical
Unreviewed
CVE-2024-44217
was published
Oct 29, 2024
XWiki allows remote code execution through the extension sheet
Critical
CVE-2024-55662
was published
for
org.xwiki.platform:xwiki-platform-repository-server-ui
(Maven)
Dec 12, 2024
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability....
Critical
Unreviewed
CVE-2024-11680
was published
Nov 26, 2024
An authentication issue was addressed with improved state management. This issue is fixed in...
Critical
Unreviewed
CVE-2024-23255
was published
Mar 8, 2024
Incorrect access control in wms-Warehouse management system-zeqp v2.20.9.1 due to the token value...
Critical
Unreviewed
CVE-2024-52732
was published
Dec 2, 2024
A misconfiguration in the fingerprint authentication mechanism of Binance: BTC, Crypto and NFTS...
Critical
Unreviewed
CVE-2024-31695
was published
Nov 15, 2024
UniFi OS 3.1 introduces a misconfiguration on consoles running UniFi Network that allows users on...
Critical
Unreviewed
CVE-2023-31997
was published
Jul 1, 2023
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2023-29381
was published
Jul 6, 2023
lunary-ai/lunary allows users unauthorized access to projects
Critical
CVE-2024-4146
was published
for
lunary
(npm)
Jun 8, 2024
•
withdrawn
GoAuthentik vulnerable to Insufficient Authorization for several API endpoints
Critical
CVE-2024-42490
was published
for
goauthentik.io
(Go)
Aug 22, 2024
fabedge has insecure permissions
Critical
CVE-2024-36536
was published
for
github.com/fabedge/fabedge
(Go)
Jul 24, 2024
In lunary-ai/lunary versions 1.2.2 through 1.2.6, an incorrect authorization vulnerability allows...
Critical
Unreviewed
CVE-2024-3379
was published
Nov 14, 2024
Sourcecodester Online Computer and Laptop Store 1.0 is vulnerable to Incorrect Access Control,...
Critical
Unreviewed
CVE-2023-31704
was published
Jul 13, 2023
ProTip!
Advisories are also available from the
GraphQL API