GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,744
Maven
5,000+
npm
4,341
NuGet
765
pip
4,113
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
396 advisories
Filter by severity
Froxlor Improper Authorization vulnerability
Moderate
CVE-2022-4868
was published
for
froxlor/froxlor
(Composer)
Dec 31, 2022
Huawei Aslan Children's Watch has an improper authorization vulnerability. Successful exploit...
Moderate
Unreviewed
CVE-2022-45874
was published
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4811
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to Improper Authorization
Moderate
CVE-2022-4802
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4798
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4804
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
The parent process would not properly check whether the Speech Synthesis feature is enabled, when...
Moderate
Unreviewed
CVE-2022-29913
was published
Dec 22, 2022
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where certain PHP...
Moderate
Unreviewed
CVE-2022-3187
was published
Dec 22, 2022
A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension...
Moderate
Unreviewed
CVE-2022-4613
was published
Dec 19, 2022
A vulnerability, which was classified as problematic, has been found in Click Studios...
Moderate
Unreviewed
CVE-2022-3876
was published
Dec 19, 2022
OpenFGA Authorization Bypass via tupleset wildcard
Moderate
CVE-2022-39341
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
OpenFGA Authorization Bypass
Moderate
CVE-2022-39342
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
OpenFGA subject to Information Disclosure via streamed-list-objects endpoint
Moderate
CVE-2022-39340
was published
for
github.com/openfga/openfga
(Go)
Oct 25, 2022
A vulnerability in the MiCollab Client API of Mitel MiCollab through 9.5.0.101 could allow an...
Moderate
Unreviewed
CVE-2022-36454
was published
Oct 25, 2022
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer...
Moderate
Unreviewed
CVE-2022-42961
was published
Oct 15, 2022
Cloud Mobility for Dell Storage versions 1.3.0 and earlier contains an Improper Access Control...
Moderate
Unreviewed
CVE-2022-34434
was published
Oct 11, 2022
Improper authorization vulnerability in Samsung Internet prior to version 18.0.4.14 allows...
Moderate
Unreviewed
CVE-2022-39873
was published
Oct 7, 2022
Bytebase allows low-privilege users to view admin projects
Moderate
CVE-2022-32170
was published
for
github.com/bytebase/bytebase
(Go)
Sep 29, 2022
Harbor fails to validate the user permissions when updating a robot account
Moderate
CVE-2022-31667
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when updating tag immutability policies
Moderate
CVE-2022-31669
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1...
Moderate
Unreviewed
CVE-2022-36848
was published
Sep 10, 2022
Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logs
Moderate
CVE-2022-31671
was published
for
github.com/goharbor/harbor
(Go)
Sep 9, 2022
The Transposh WordPress Translation plugin for WordPress is vulnerable to unauthorized setting...
Moderate
Unreviewed
CVE-2022-2461
was published
Sep 7, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey...
Moderate
Unreviewed
CVE-2022-32838
was published
Aug 25, 2022
Using off-the-shelf commodity hardware, the Unitree Go 1 robotics platform version H0.1.7 and H0...
Moderate
Unreviewed
CVE-2022-2675
was published
Aug 6, 2022
ProTip!
Advisories are also available from the
GraphQL API