GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
69 advisories
Filter by severity
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3). The affected...
High
Unreviewed
CVE-2024-29119
was published
Nov 12, 2024
Incorrect Privilege Assignment vulnerability in Matt Whiteman Bulk Change Role allows Privilege...
High
Unreviewed
CVE-2024-50504
was published
Oct 30, 2024
Incorrect Privilege Assignment vulnerability in Azexo Marketing Automation by AZEXO allows...
High
Unreviewed
CVE-2024-50506
was published
Oct 30, 2024
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows...
High
Unreviewed
CVE-2024-50550
was published
Oct 29, 2024
Incorrect Privilege Assignment vulnerability in Stack Themes Bstone Demo Importer allows...
High
Unreviewed
CVE-2024-50481
was published
Oct 29, 2024
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2...
High
Unreviewed
CVE-2024-47904
was published
Oct 23, 2024
: Incorrect Privilege Assignment vulnerability in Gerry Ntabuhashe GERRYWORKS Post by Mail allows...
High
Unreviewed
CVE-2024-49608
was published
Oct 20, 2024
Vault Community Edition privilege escalation vulnerability
High
CVE-2024-9180
was published
for
github.com/hashicorp/vault
(Go)
Oct 10, 2024
Incorrect Privilege Assignment vulnerability in themexpo RS-Members allows Privilege Escalation...
High
Unreviewed
CVE-2024-49219
was published
Oct 17, 2024
This vulnerability exists in Shilpi Client Dashboard due to lack of authorization for...
High
Unreviewed
CVE-2024-47653
was published
Oct 4, 2024
Parcel mismatch in AuthenticationConfig prior to SMR Aug-2023 Release 1 allows local attacker to...
High
Unreviewed
CVE-2023-30691
was published
Aug 10, 2023
Improper privilege management vulnerability in MMIGroup prior to SMR Aug-2023 Release 1 allows...
High
Unreviewed
CVE-2023-30680
was published
Aug 10, 2023
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an...
High
Unreviewed
CVE-2024-9519
was published
Oct 10, 2024
In startActivityInner of ActivityStarter.java, there is a possible way to launch an activity into...
High
Unreviewed
CVE-2023-21269
was published
Aug 14, 2023
Hashicorp Vault Incorrect Permission Assignment for Critical Resource vulnerability
High
CVE-2023-5077
was published
for
github.com/hashicorp/vault
(Go)
Sep 29, 2023
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to...
High
Unreviewed
CVE-2023-28956
was published
Jun 22, 2023
Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
High
CVE-2023-2816
was published
for
github.com/hashicorp/consul
(Go)
Jun 3, 2023
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High
CVE-2023-3518
was published
for
github.com/hashicorp/consul
(Go)
Aug 9, 2023
Incorrect Privilege Assignment in Jinja2
High
CVE-2014-1402
was published
for
Jinja2
(pip)
May 14, 2022
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom...
High
Unreviewed
CVE-2023-49647
was published
Jan 13, 2024
Incorrect Privilege Assignment vulnerability in favethemes Houzez houzez allows Privilege...
High
Unreviewed
CVE-2024-22303
was published
Sep 17, 2024
Privilege Escalation vulnerability in favethemes Houzez Login Register houzez-login-register.This...
High
Unreviewed
CVE-2024-21743
was published
Sep 17, 2024
The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in...
High
Unreviewed
CVE-2024-8253
was published
Sep 11, 2024
IBM MQ Operator 2.0.26 and 3.2.4 could allow an authenticated user in a specifically defined role...
High
Unreviewed
CVE-2024-40681
was published
Sep 7, 2024
Insecure permissions in hwameistor v0.14.3 allows attackers to access sensitive data and escalate...
High
Unreviewed
CVE-2024-36534
was published
Jul 24, 2024
ProTip!
Advisories are also available from the
GraphQL API