GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,759
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
11,340 advisories
Filter by severity
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected...
Low
Unreviewed
CVE-2023-6615
was published
Dec 8, 2023
A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown...
Low
Unreviewed
CVE-2023-6613
was published
Dec 8, 2023
A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this...
Low
Unreviewed
CVE-2023-6614
was published
Dec 8, 2023
eventing-gitlab vulnerable to denial of service, caused by improper enforcement of the timeout on individual read operations
Low
GHSA-99jv-8292-2hpm
was published
for
knative.dev/eventing-gitlab
(Go)
Dec 8, 2023
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background...
Low
Unreviewed
CVE-2023-5870
was published
Dec 10, 2023
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered...
Low
Unreviewed
CVE-2023-6194
was published
Dec 11, 2023
Stale copy of the public suffix list
Low
GHSA-w4x6-hh3x-wjrx
was published
for
Gsemac.Net
(NuGet)
Dec 11, 2023
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2...
Low
Unreviewed
CVE-2023-42874
was published
Dec 12, 2023
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform...
Low
Unreviewed
CVE-2023-49578
was published
Dec 12, 2023
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient...
Low
Unreviewed
CVE-2023-49058
was published
Dec 12, 2023
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing...
Low
Unreviewed
CVE-2023-6547
was published
Dec 12, 2023
Mattermost fails to perform correct authorization checks when creating a playbook action,...
Low
Unreviewed
CVE-2023-6727
was published
Dec 12, 2023
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API...
Low
Unreviewed
CVE-2023-48430
was published
Dec 12, 2023
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI...
Low
Unreviewed
CVE-2023-48429
was published
Dec 12, 2023
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious...
Low
Unreviewed
CVE-2023-6710
was published
Dec 13, 2023
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and...
Low
Unreviewed
CVE-2023-47536
was published
Dec 13, 2023
An improper neutralization of input during web page generation ('cross-site scripting') in...
Low
Unreviewed
CVE-2023-45587
was published
Dec 13, 2023
A improper neutralization of input during web page generation ('cross-site scripting') in...
Low
Unreviewed
CVE-2023-41844
was published
Dec 13, 2023
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11...
Low
Unreviewed
CVE-2023-6381
was published
Dec 13, 2023
Possible injection of HTML into user invite mails
Low
CVE-2023-38694
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
Backoffice User can bypass "Publish" restriction
Low
CVE-2023-48227
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
Using the directory back payload (“/../”) in a package name allows placement of package in other folders.
Low
CVE-2023-49089
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
SMTP misconfiguration leading to "Forgot Password" exploit that leaks registered user email.
Low
CVE-2023-49274
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
Brute force exploit can be used to collect valid usernames
Low
CVE-2023-49278
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
Stored XSS via SVG File Upload
Low
CVE-2023-49279
was published
for
Umbraco.CMS
(NuGet)
Dec 13, 2023
ProTip!
Advisories are also available from the
GraphQL API