GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
434 advisories
Filter by severity
Under certain conditions, Support Web Pages of SAP NetWeaver Process Integration (PI) - versions...
Moderate
Unreviewed
CVE-2024-28163
was published
Mar 12, 2024
Under certain condition SAP NetWeaver (Enterprise Portal) - version 7.50 allows an attacker to...
Moderate
Unreviewed
CVE-2024-25645
was published
Mar 12, 2024
Under certain conditions SAP NetWeaver WSRM - version 7.50, allows an attacker to access...
Moderate
Unreviewed
CVE-2024-25644
was published
Mar 12, 2024
SAP NetWeaver Application Server (ABAP) - versions KERNEL 7.53, KERNEL 7.54, KERNEL 7.77, KERNEL...
Moderate
Unreviewed
CVE-2024-24740
was published
Feb 13, 2024
Spring Security's spring-security.xsd file is world writable
Moderate
CVE-2023-34042
was published
for
org.springframework.security:spring-security-config
(Maven)
Feb 6, 2024
Moby (Docker Engine) Insufficiently restricted permissions on data directory
Moderate
CVE-2021-41091
was published
for
github.com/docker/docker
(Go)
Jan 31, 2024
Privilege Escalation in HashiCorp Consul
Moderate
CVE-2020-28053
was published
for
github.com/hashicorp/consul
(Go)
Jan 31, 2024
Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
Moderate
CVE-2023-48714
was published
for
silverstripe/framework
(Composer)
Jan 23, 2024
Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some...
Moderate
Unreviewed
CVE-2023-38541
was published
Jan 19, 2024
The Easy Social Feed plugin for WordPress is vulnerable to unauthorized modification of data due...
Moderate
Unreviewed
CVE-2023-6883
was published
Jan 11, 2024
The WP 2FA – Two-factor authentication for WordPress plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2023-6506
was published
Jan 11, 2024
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-21305
was published
Jan 9, 2024
There is a local privilege escalation vulnerability of ZTE's ZXCLOUD iRAI.Attackers with regular...
Moderate
Unreviewed
CVE-2023-41776
was published
Jan 3, 2024
A vulnerability classified as problematic has been found in PHPGurukul Online Notes Sharing...
Moderate
Unreviewed
CVE-2023-7055
was published
Dec 22, 2023
There is a weak folder permission vulnerability in ZTE's ZXCLOUD iRAI product. Due to weak...
Moderate
Unreviewed
CVE-2023-25648
was published
Dec 14, 2023
A logic issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.2, macOS...
Moderate
Unreviewed
CVE-2023-42924
was published
Dec 12, 2023
The FACSChorus software database can be accessed directly with the privileges of the currently...
Moderate
Unreviewed
CVE-2023-29065
was published
Nov 28, 2023
The WP Hotel Booking WordPress plugin before 2.0.8 does not have authorisation and CSRF checks,...
Moderate
Unreviewed
CVE-2023-5651
was published
Nov 20, 2023
xxl-job-admin vulnerable to Insecure Permissions
Moderate
CVE-2023-48087
was published
for
com.xuxueli:xxl-job-admin
(Maven)
Nov 15, 2023
Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2...
Moderate
Unreviewed
CVE-2023-34314
was published
Nov 14, 2023
Insecure inherited permissions in the installer for some Intel Server Configuration Utility...
Moderate
Unreviewed
CVE-2023-34997
was published
Nov 14, 2023
Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16...
Moderate
Unreviewed
CVE-2023-39230
was published
Nov 14, 2023
Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software...
Moderate
Unreviewed
CVE-2022-41700
was published
Nov 14, 2023
Insecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before...
Moderate
Unreviewed
CVE-2022-33898
was published
Nov 14, 2023
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2...
Moderate
Unreviewed
CVE-2023-36633
was published
Nov 14, 2023
ProTip!
Advisories are also available from the
GraphQL API