GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
884 advisories
Filter by severity
On-Premises Data Gateway Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21403
was published
Jan 14, 2025
Incorrect Authorization vulnerability in Drupal Pages Restriction Access allows Forceful Browsing...
Moderate
Unreviewed
CVE-2024-13302
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal OhDear Integration allows Forceful Browsing.This...
Moderate
Unreviewed
CVE-2024-13290
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Responsive and off-canvas menu allows Forceful...
Moderate
Unreviewed
CVE-2024-13266
was published
Jan 9, 2025
Incorrect Authorization vulnerability in Drupal Commerce View Receipt allows Forceful Browsing...
Moderate
Unreviewed
CVE-2024-13257
was published
Jan 9, 2025
The WebChannel API, which is used to transport various information across processes, did not...
Moderate
Unreviewed
CVE-2025-0237
was published
Jan 7, 2025
Some Honor products are affected by incorrect privilege assignment vulnerability, successful...
Moderate
Unreviewed
CVE-2024-47148
was published
Dec 26, 2024
In JetBrains TeamCity before 2024.12 improper access control allowed viewing details of...
Moderate
Unreviewed
CVE-2024-56348
was published
Dec 20, 2024
In JetBrains TeamCity before 2024.12 build credentials allowed unauthorized viewing of projects
Moderate
Unreviewed
CVE-2024-56350
was published
Dec 20, 2024
Arista NG Firewall uvm_login Incorrect Authorization Privilege Escalation Vulnerability. This...
Moderate
Unreviewed
CVE-2024-12831
was published
Dec 20, 2024
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5...
Moderate
Unreviewed
CVE-2024-8650
was published
Dec 16, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5...
Moderate
Unreviewed
CVE-2024-8116
was published
Dec 16, 2024
The issue was addressed with improved permissions logic. This issue is fixed in macOS Sequoia 15...
Moderate
Unreviewed
CVE-2024-54495
was published
Dec 12, 2024
Mattermost versions 9.7.x <= 9.7.5, 9.8.x <= 9.8.2 and 9.9.x <= 9.9.2 fail to properly propagate...
Moderate
Unreviewed
CVE-2024-12247
was published
Dec 5, 2024
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier...
Moderate
Unreviewed
CVE-2024-12196
was published
Dec 4, 2024
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and...
Moderate
Unreviewed
CVE-2024-12148
was published
Dec 4, 2024
Incorrect authorization vulnerability in ActionRule webapi component in Synology Surveillance...
Moderate
Unreviewed
CVE-2023-52944
was published
Dec 4, 2024
Incorrect authorization vulnerability in Alert.Setting webapi component in Synology Surveillance...
Moderate
Unreviewed
CVE-2023-52943
was published
Dec 4, 2024
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5...
Moderate
Unreviewed
CVE-2024-11669
was published
Nov 26, 2024
Incorrect access control in Adapt Learning Adapt Authoring Tool <= 0.11.3 allows attackers with...
Moderate
Unreviewed
CVE-2024-50671
was published
Nov 25, 2024
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager...
Moderate
Unreviewed
CVE-2024-11672
was published
Nov 25, 2024
Incorrect authorization in the permission validation component of Devolutions Remote Desktop...
Moderate
Unreviewed
CVE-2024-11670
was published
Nov 25, 2024
baltic-it TOPqw Webportal v1.35.283.2 is vulnerable to Incorrect Access Control in the User...
Moderate
Unreviewed
CVE-2024-45877
was published
Nov 13, 2024
An Improper Authorization (Access Control Misconfiguration) vulnerability in MGT-COMMERCE GmbH v2...
Moderate
Unreviewed
CVE-2024-44765
was published
Nov 8, 2024
A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated,...
Moderate
Unreviewed
CVE-2024-20537
was published
Nov 6, 2024
ProTip!
Advisories are also available from the
GraphQL API