GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
696 advisories
Filter by severity
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to...
High
Unreviewed
CVE-2024-33383
was published
Apr 30, 2024
ethOS through 1.3.3 ships with SSH host keys baked into the installation image, which allows man...
Critical
Unreviewed
CVE-2019-19755
was published
Apr 30, 2024
Insecure Direct Object References (IDOR) vulnerability in Hospital Management System 1.0 allows...
High
Unreviewed
CVE-2024-28320
was published
Apr 29, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Fabio Rinaldi Crelly Slider...
Moderate
Unreviewed
CVE-2024-33542
was published
Apr 29, 2024
An issue was discovered in Zammad before 6.3.0. The Zammad Upload Cache uses insecure, partially...
Critical
Unreviewed
CVE-2024-33668
was published
Apr 26, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This...
Moderate
Unreviewed
CVE-2024-32772
was published
Apr 24, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This...
Moderate
Unreviewed
CVE-2024-32808
was published
Apr 24, 2024
Authorization Bypass Through User-Controlled Key vulnerability in FeedbackWP Rate my Post – WP...
Moderate
Unreviewed
CVE-2024-32823
was published
Apr 24, 2024
Webid v1.2.1 suffers from an Insecure Direct Object Reference (IDOR) - Broken Access Control...
High
Unreviewed
CVE-2024-32166
was published
Apr 19, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Wpmet Wp Ultimate Review.This...
Moderate
Unreviewed
CVE-2024-32683
was published
Apr 19, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Plechev Andrey WP-Recall.This...
Moderate
Unreviewed
CVE-2024-32604
was published
Apr 18, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
Critical
Unreviewed
CVE-2024-1626
was published
Apr 16, 2024
A potential security vulnerability has been identified in HPE FlexFabric and FlexNetwork series...
Moderate
Unreviewed
CVE-2024-22439
was published
Apr 15, 2024
Reportico affected by Incorrect Access Control
Moderate
CVE-2023-48865
was published
for
reportico-web/reportico
(Composer)
Apr 12, 2024
An issue in ZKTeko BioTime v.8.5.4 and before allows a remote attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2023-51141
was published
Apr 11, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
High
Unreviewed
CVE-2024-1625
was published
Apr 10, 2024
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct...
Moderate
Unreviewed
CVE-2024-1289
was published
Apr 9, 2024
A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7....
High
Unreviewed
CVE-2023-6317
was published
Apr 9, 2024
Insecure Direct Object Reference (IDOR) in GNU Savane v.3.12 and before allows a remote attacker...
Unknown
Unreviewed
CVE-2024-27630
was published
Apr 8, 2024
In TOTOLINK EX200 V4.0.3c.7314_B20191204, an attacker can obtain the configuration file without...
Critical
Unreviewed
CVE-2024-31815
was published
Apr 8, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Repute Infosystems BookingPress...
Moderate
Unreviewed
CVE-2024-31296
was published
Apr 7, 2024
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid.This...
Moderate
Unreviewed
CVE-2024-31291
was published
Apr 7, 2024
Grafana: Users outside an organization can delete a snapshot with its key
High
CVE-2024-1313
was published
for
github.com/grafana/grafana
(Go)
Apr 5, 2024
Authorization Bypass Through User-Controlled Key vulnerability in ExtremePacs Extreme XDS allows...
High
Unreviewed
CVE-2023-6523
was published
Apr 5, 2024
A vulnerability, which was classified as critical, has been found in SourceCodester Computer...
Moderate
Unreviewed
CVE-2024-3139
was published
Apr 2, 2024
ProTip!
Advisories are also available from the
GraphQL API