GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
52 advisories
Filter by severity
Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java
Moderate
CVE-2022-21363
was published
for
mysql:mysql-connector-java
(Maven)
Jan 20, 2022
Missing permissions check in Jenkins Core
Moderate
CVE-2016-3725
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V2.0). Due to...
High
Unreviewed
CVE-2019-6570
was published
May 13, 2022
Missing permissions check in Liferay Portal
Moderate
CVE-2022-42126
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
usememos/memos vulnerable to Improper Handling of Insufficient Permissions or Privileges
Moderate
CVE-2022-4863
was published
for
github.com/usememos/memos
(Go)
Dec 30, 2022
`cilium-cli` disables etcd authorization for clustermesh clusters
Moderate
CVE-2023-28114
was published
for
github.com/cilium/cilium-cli
(Go)
Mar 21, 2023
Apiman vulnerable to permissions bypass due to missing check on API key URL
Moderate
CVE-2023-28640
was published
for
io.apiman:apiman-manager-api-rest-impl
(Maven)
Mar 27, 2023
Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to...
Low
Unreviewed
CVE-2022-39885
was published
Nov 10, 2022
Improper access control vulnerability in IpcRxServiceModeBigDataInfo in RIL prior to SMR Nov-2022...
Low
Unreviewed
CVE-2022-39886
was published
Nov 10, 2022
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in a kernel mode layer...
High
Unreviewed
CVE-2023-0181
was published
Apr 1, 2023
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel driver package, where...
Moderate
Unreviewed
CVE-2022-21814
was published
Feb 8, 2022
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient...
Moderate
Unreviewed
CVE-2023-43087
was published
Nov 2, 2023
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows...
Moderate
Unreviewed
CVE-2020-8219
was published
May 24, 2022
Improper privilege handling in Apache Accumulo
High
CVE-2020-17533
was published
for
org.apache.accumulo:accumulo-master
(Maven)
Feb 9, 2022
Dell Power Manager, versions prior to 3.14, contain an Improper Authorization vulnerability in...
High
Unreviewed
CVE-2023-25543
was published
Feb 6, 2024
A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors....
Moderate
Unreviewed
CVE-2024-0560
was published
Feb 28, 2024
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 ...
Moderate
Unreviewed
CVE-2023-2020
was published
Apr 18, 2023
Dell PowerScale OneFS 8.2x -9.5x contains a privilege escalation vulnerability. A local attacker...
Moderate
Unreviewed
CVE-2023-32489
was published
Aug 16, 2023
Matrix IRC Bridge truncated content of messages can be leaked
Moderate
CVE-2024-32000
was published
for
matrix-appservice-irc
(npm)
Apr 11, 2024
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Low
CVE-2024-32882
was published
for
wagtail
(pip)
May 1, 2024
In JetBrains TeamCity before 2024.03.1 commit status publisher didn't check project scope of the...
Moderate
Unreviewed
CVE-2024-35301
was published
May 16, 2024
Nautobot dynamic-group-members doesn't enforce permission restrictions on member objects
Moderate
CVE-2024-36112
was published
for
nautobot
(pip)
May 29, 2024
Improper Handling of Insufficient Permissions in `wagtail.contrib.settings`
Moderate
CVE-2024-35228
was published
for
wagtail
(pip)
Jun 2, 2024
Lack of privilege checking when processing a redaction in Conduit versions v0.6.0 and lower,...
High
Unreviewed
CVE-2024-6302
was published
Jun 25, 2024
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission...
Critical
Unreviewed
CVE-2024-1608
was published
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API