GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,168
Erlang
30
GitHub Actions
19
Go
1,978
Maven
5,000+
npm
3,698
NuGet
656
pip
3,315
Pub
11
RubyGems
882
Rust
832
Swift
35
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
Kubelet Incorrect Privilege Assignment
Moderate
CVE-2019-11245
was published
for
k8s.io/kubernetes/cmd/kubelet
(Go)
Apr 24, 2024
Various software builds for the following TCL devices (30Z, A3X, 20XE, 10L) leak the device IMEI...
High
Unreviewed
CVE-2023-38298
was published
Apr 22, 2024
An issue in sanluan flipped-aurora gin-vue-admin 2.4.x allows an attacker to escalate privileges...
Moderate
Unreviewed
CVE-2024-31760
was published
Apr 17, 2024
A vulnerability in the SSH client feature of Cisco IOS XR Software for Cisco 8000 Series Routers...
High
Unreviewed
CVE-2024-20320
was published
Mar 13, 2024
An issue was discovered in Couchbase Server before 7.2.x before 7.2.4. otpCookie is shown with...
High
Unreviewed
CVE-2023-50437
was published
Feb 29, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 16.5 before 16.7.6...
Moderate
Unreviewed
CVE-2023-6477
was published
Feb 22, 2024
An issue was discovered in BeyondTrust Privilege Management for Windows before 24.1. When an low...
Moderate
Unreviewed
CVE-2024-25083
was published
Feb 16, 2024
In createFromParcel of UsbConfiguration.java, there is a possible background activity launch (BAL...
High
Unreviewed
CVE-2023-40109
was published
Feb 16, 2024
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be...
Moderate
Unreviewed
CVE-2024-23976
was published
Feb 14, 2024
Incorrect Privilege Assignment vulnerability in Mitsubishi Electric Corporation MELSEC iQ-R...
Moderate
Unreviewed
CVE-2023-6815
was published
Feb 13, 2024
A privilege escalation vulnerability was reported in some Lenovo tablet products that could allow...
Moderate
Unreviewed
CVE-2023-5080
was published
Jan 19, 2024
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom...
High
Unreviewed
CVE-2023-49647
was published
Jan 13, 2024
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper...
Moderate
Unreviewed
CVE-2023-47140
was published
Jan 8, 2024
The FACSChorus software does not properly assign data access privileges for operating system user...
Low
Unreviewed
CVE-2023-29066
was published
Nov 28, 2023
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The...
High
Unreviewed
CVE-2023-5913
was published
Nov 8, 2023
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
High
CVE-2023-5077
was published
for
github.com/hashicorp/vault
(Go)
Sep 29, 2023
The BAN Users plugin for WordPress is vulnerable to privilege escalation in versions up to, and...
High
Unreviewed
CVE-2023-4153
was published
Sep 13, 2023
SearchBlox before Version 9.2.1 is vulnerable to Privileged Escalation-Lower user is able to...
High
Unreviewed
CVE-2020-10129
was published
Sep 6, 2023
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into...
High
Unreviewed
CVE-2023-21269
was published
Aug 14, 2023
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to...
High
Unreviewed
CVE-2023-30691
was published
Aug 10, 2023
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows...
High
Unreviewed
CVE-2023-30680
was published
Aug 10, 2023
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High
CVE-2023-3518
was published
for
github.com/hashicorp/consul
(Go)
Aug 9, 2023
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain...
High
Unreviewed
CVE-2023-39173
was published
Jul 25, 2023
Nomad Search API Leaks Information About CSI Plugins
Moderate
CVE-2023-3300
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
Nomad ACL Policies without Label are Applied to Unexpected Resources
Moderate
CVE-2023-3072
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
ProTip!
Advisories are also available from the
GraphQL API