GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,198
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,702
NuGet
660
pip
3,328
Pub
11
RubyGems
883
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
129 advisories
Filter by severity
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers
High
CVE-2023-3518
was published
for
github.com/hashicorp/consul
(Go)
Aug 9, 2023
In JetBrains TeamCity before 2023.05.2 a token with limited permissions could be used to gain...
High
Unreviewed
CVE-2023-39173
was published
Jul 25, 2023
Nomad Search API Leaks Information About CSI Plugins
Moderate
CVE-2023-3300
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
Nomad ACL Policies without Label are Applied to Unexpected Resources
Moderate
CVE-2023-3072
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
IBM Spectrum Protect Backup-Archive Client 8.1.0.0 through 8.1.17.2 may allow a local user to...
High
Unreviewed
CVE-2023-28956
was published
Jun 22, 2023
AWS CDK EKS overly permissive trust policies
Moderate
CVE-2023-35165
was published
for
@aws-cdk/aws-eks
(npm)
Jun 19, 2023
An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.1 before 15...
Moderate
Unreviewed
CVE-2023-2485
was published
Jun 7, 2023
Hashicorp Consul allows user with service:write permissions to patch remote proxy instances
High
CVE-2023-2816
was published
for
github.com/hashicorp/consul
(Go)
Jun 3, 2023
This vulnerability exposes a network port in minikube running on macOS with Docker driver that...
Critical
Unreviewed
CVE-2023-1174
was published
May 24, 2023
The WP Data Access plugin for WordPress is vulnerable to privilege escalation in versions up to,...
High
Unreviewed
CVE-2023-1874
was published
Apr 12, 2023
text_helpers uses web link to untrusted target with window.opener access
Moderate
CVE-2020-36624
was published
for
text_helpers
(RubyGems)
Dec 22, 2022
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension...
Moderate
Unreviewed
CVE-2022-4613
was published
Dec 19, 2022
A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this...
High
Unreviewed
CVE-2022-4281
was published
Dec 5, 2022
A vulnerability, which was classified as critical, has been found in SourceCodester Human...
Critical
Unreviewed
CVE-2022-4273
was published
Dec 3, 2022
A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by...
Critical
Unreviewed
CVE-2022-4272
was published
Dec 3, 2022
A vulnerability, which was classified as critical, was found in SourceCodester Event Registration...
Critical
Unreviewed
CVE-2022-4232
was published
Nov 30, 2022
A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects...
Critical
Unreviewed
CVE-2022-3735
was published
Oct 28, 2022
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has...
High
Unreviewed
CVE-2022-3549
was published
Oct 17, 2022
A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified...
High
Unreviewed
CVE-2022-3496
was published
Oct 14, 2022
A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and...
Critical
Unreviewed
CVE-2022-3458
was published
Oct 12, 2022
A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance...
High
Unreviewed
CVE-2022-3436
was published
Oct 10, 2022
Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
High
Unreviewed
CVE-2022-2626
was published
Aug 6, 2022
The authentication mechanism used by poll workers to administer voting using the tested version...
High
Unreviewed
CVE-2022-1746
was published
Jun 25, 2022
An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11...
High
Unreviewed
CVE-2021-20264
was published
May 24, 2022
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an...
High
Unreviewed
CVE-2021-1594
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API