GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
123 advisories
Filter by severity
Missing Authorization vulnerability in ThemeIsle Otter - Gutenberg Block allows Exploiting...
Low
Unreviewed
CVE-2024-51671
was published
Nov 19, 2024
In multiple functions of healthconnect, there is a possible leakage of exercise route data due to...
Low
Unreviewed
CVE-2024-0052
was published
Mar 11, 2024
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a...
Low
Unreviewed
CVE-2024-0037
was published
Feb 16, 2024
Missing Authorization vulnerability in Brainstorm Force Spectra allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2023-23825
was published
Dec 9, 2024
Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting...
Low
Unreviewed
CVE-2023-23814
was published
Dec 9, 2024
Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord,...
Low
Unreviewed
CVE-2023-24375
was published
Dec 9, 2024
Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting...
Low
Unreviewed
CVE-2023-28168
was published
Dec 9, 2024
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file...
Low
Unreviewed
CVE-2024-12300
was published
Dec 13, 2024
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2022-45819
was published
Dec 13, 2024
Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2023-41695
was published
Dec 13, 2024
The Spacer plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
Low
Unreviewed
CVE-2024-10527
was published
Jan 7, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and...
Low
Unreviewed
CVE-2024-40839
was published
Jan 15, 2025
In JetBrains YouTrack before 2024.3.51866 improper access control allowed listing of project...
Low
Unreviewed
CVE-2024-54155
was published
Dec 4, 2024
In JetBrains YouTrack before 2024.3.51866 unauthenticated database backup download was possible...
Low
Unreviewed
CVE-2024-54153
was published
Dec 4, 2024
Apache NiFi: Missing Complete Authorization for Parameter and Service References
Low
CVE-2024-56512
was published
for
org.apache.nifi:nifi-web-api
(Maven)
Dec 28, 2024
Leantime has Missing Authorization Check for Host Parameter
Low
GHSA-3hfj-qcvj-4hx8
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
SAP Just In Time(JIT) does not perform necessary authorization checks for an authenticated user,...
Low
Unreviewed
CVE-2025-26655
was published
Mar 11, 2025
The eDocument Cockpit (Inbound NF-e) in SAP Electronic Invoicing for Brazil allows an...
Low
Unreviewed
CVE-2025-27432
was published
Mar 11, 2025
In affected versions of Octopus Deploy it was possible to upload files to unexpected locations on...
Low
Unreviewed
CVE-2025-0526
was published
Feb 11, 2025
Missing Authorization vulnerability in fatcatapps Quiz Cat allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2025-30877
was published
Mar 27, 2025
A Broken Object Level Authorization vulnerability in the component /households/permissions of hay...
Low
Unreviewed
CVE-2024-55070
was published
Mar 27, 2025
Missing authorization in PostgreSQL built-in views pg_stats_ext and pg_stats_ext_exprs allows an...
Low
Unreviewed
CVE-2024-4317
was published
May 14, 2024
Moodle doesn't properly check role
Low
CVE-2010-1617
was published
for
moodle/moodle
(Composer)
May 13, 2022
In multiple locations of WifiDialogActivity.java, there is a possible limited lockscreen bypass...
Low
Unreviewed
CVE-2022-20529
was published
Dec 20, 2022
The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins...
Low
Unreviewed
CVE-2017-5930
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API