GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
11,339 advisories
Filter by severity
Unauthenticated db-file-storage views
Low
CVE-2023-50263
was published
for
nautobot
(pip)
Dec 13, 2023
Broken access control in Silverpeas
Low
CVE-2023-47320
was published
for
org.silverpeas.core:silverpeas-core-war
(Maven)
Dec 13, 2023
An improper privilege management vulnerability in Palo Alto Networks PAN-OS software enables an...
Low
Unreviewed
CVE-2023-6793
was published
Dec 13, 2023
Sensitive information disclosure and manipulation due to missing authorization. The following...
Low
Unreviewed
CVE-2023-48676
was published
Dec 14, 2023
Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMut
Low
GHSA-3mv5-343c-w2qg
was published
for
zerocopy
(Rust)
Dec 15, 2023
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2023-48608
was published
Dec 15, 2023
An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4...
Low
Unreviewed
CVE-2023-3511
was published
Dec 15, 2023
nvdApiKey is logged in debug mode
Low
GHSA-qqhq-8r2c-c3f5
was published
for
org.owasp:dependency-check-ant
(Maven)
Dec 15, 2023
HCL Connections is vulnerable to an information disclosure vulnerability which could allow a user...
Low
Unreviewed
CVE-2023-28022
was published
Dec 16, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Low
CVE-2023-50708
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000...
Low
Unreviewed
CVE-2023-22439
was published
Dec 19, 2023
Sensitive information uncleared after debug/power state transition in the Controller 6000 could...
Low
Unreviewed
CVE-2023-41967
was published
Dec 19, 2023
A flaw was found in the libssh implements abstract layer for message digest (MD) operations...
Low
Unreviewed
CVE-2023-6918
was published
Dec 19, 2023
A vulnerability has been found in SourceCodester Online Student Management System 1.0 and...
Low
Unreviewed
CVE-2023-6945
was published
Dec 19, 2023
Authorization Bypass Through User-Controlled Key vulnerability in gVectors Team Comments –...
Low
Unreviewed
CVE-2023-46311
was published
Dec 20, 2023
Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad
Low
CVE-2023-7035
was published
for
automad/automad
(Composer)
Dec 21, 2023
•
withdrawn
Authenticated Blind SSRF in automad/automad
Low
CVE-2023-7037
was published
for
automad/automad
(Composer)
Dec 21, 2023
A race condition in GitHub Enterprise Server allowed an existing admin to maintain permissions on...
Low
Unreviewed
CVE-2023-6690
was published
Dec 21, 2023
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed...
Low
Unreviewed
CVE-2023-51380
was published
Dec 21, 2023
A vulnerability was found in PHPGurukul Online Notes Sharing System 1.0. It has been declared as...
Low
Unreviewed
CVE-2023-7053
was published
Dec 22, 2023
A vulnerability classified as problematic was found in code-projects Faculty Management System 1...
Low
Unreviewed
CVE-2023-7056
was published
Dec 22, 2023
Nautobot missing object-level permissions enforcement when running Job Buttons
Low
CVE-2023-51649
was published
for
nautobot
(pip)
Dec 22, 2023
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as...
Low
Unreviewed
CVE-2014-125108
was published
Dec 23, 2023
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret...
Low
Unreviewed
CVE-2023-7098
was published
Dec 25, 2023
A vulnerability was found in code-projects Intern Membership Management System 2.0. It has been...
Low
Unreviewed
CVE-2023-7132
was published
Dec 28, 2023
ProTip!
Advisories are also available from the
GraphQL API