GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,340 advisories
Filter by severity
Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing...
Unknown
Unreviewed
CVE-2024-13302
was published
Jan 9, 2025
Vaultwarden vulnerable to user impersonation
High
CVE-2024-55225
was published
for
vaultwarden
(Rust)
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful...
Unknown
Unreviewed
CVE-2024-13266
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Freelinking allows Forceful Browsing.This issue...
Unknown
Unreviewed
CVE-2024-13270
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Content Entity Clone allows Forceful Browsing...
Unknown
Unreviewed
CVE-2024-13271
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Smart IP Ban allows Forceful Browsing.This issue...
Unknown
Unreviewed
CVE-2024-13277
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Diff allows Functionality Misuse.This issue...
Unknown
Unreviewed
CVE-2024-13278
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Monster Menus allows Forceful Browsing.This issue...
Unknown
Unreviewed
CVE-2024-13281
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Basic HTTP Authentication allows Forceful...
Unknown
Unreviewed
CVE-2024-13291
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This...
Unknown
Unreviewed
CVE-2024-13290
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Block permissions allows Forceful Browsing.This...
Unknown
Unreviewed
CVE-2024-13282
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Advanced PWA inc Push Notifications allows...
Unknown
Unreviewed
CVE-2024-13253
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Drupal REST & JSON API Authentication allows...
Unknown
Unreviewed
CVE-2024-13258
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing...
Unknown
Unreviewed
CVE-2024-13257
was published
Jan 9, 2025
Mattermost Incorrect Authorization vulnerability
Low
CVE-2025-22449
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Jan 9, 2025
The WebChannel API, which is used to transport various information across processes, did not...
Moderate
Unreviewed
CVE-2025-0237
was published
Jan 7, 2025
Letta (previously MemGPT) incorrect access control vulnerability
High
CVE-2024-39025
was published
for
letta
(pip)
Dec 27, 2024
An improper access control vulnerability exists in SimplCommerce at commit...
High
Unreviewed
CVE-2024-50945
was published
Dec 27, 2024
Some Honor products are affected by incorrect privilege assignment vulnerability, successful...
Low
Unreviewed
CVE-2024-47157
was published
Dec 26, 2024
Some Honor products are affected by incorrect privilege assignment vulnerability, successful...
Moderate
Unreviewed
CVE-2024-47148
was published
Dec 26, 2024
Oqtane Framework Insecure Direct Object Reference vulnerability
Low
CVE-2024-55186
was published
for
Oqtane.Client
(NuGet)
Dec 20, 2024
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of...
Moderate
Unreviewed
CVE-2024-56348
was published
Dec 20, 2024
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
Moderate
Unreviewed
CVE-2024-56350
was published
Dec 20, 2024
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This...
Moderate
Unreviewed
CVE-2024-12831
was published
Dec 20, 2024
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android...
Critical
Unreviewed
CVE-2023-4617
was published
Dec 19, 2024
ProTip!
Advisories are also available from the
GraphQL API