GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,270
Erlang
31
GitHub Actions
21
Go
2,044
Maven
5,000+
npm
3,736
NuGet
663
pip
3,414
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in...
Moderate
Unreviewed
CVE-2024-28228
was published
Mar 7, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.1, macOS...
Moderate
Unreviewed
CVE-2023-42889
was published
Feb 21, 2024
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Moderate
CVE-2024-21494
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows...
Moderate
Unreviewed
CVE-2023-7169
was published
Feb 8, 2024
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local...
Moderate
Unreviewed
CVE-2023-6044
was published
Jan 19, 2024
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a...
Moderate
Unreviewed
CVE-2023-4001
was published
Jan 15, 2024
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and...
Moderate
Unreviewed
CVE-2024-0454
was published
Jan 12, 2024
Header spoofing in caddy-geo-ip
Moderate
CVE-2023-50463
was published
for
github.com/shift72/caddy-geo-ip
(Go)
Dec 11, 2023
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20245
was published
Nov 1, 2023
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20256
was published
Nov 1, 2023
Multiple Cisco products are affected by a vulnerability in Snort access control policies that...
Moderate
Unreviewed
CVE-2023-20246
was published
Nov 1, 2023
An authentication bypass by spoofing of a device with a synthetic IP address is possible in...
Moderate
Unreviewed
CVE-2023-28803
was published
Oct 23, 2023
pretix potential IP address spoofing vulnerability
Moderate
CVE-2023-44463
was published
for
pretix
(pip)
Oct 2, 2023
The DoLogin Security WordPress plugin before 3.7 uses headers such as the X-Forwarded-For to...
Moderate
Unreviewed
CVE-2023-4631
was published
Sep 25, 2023
This Activity Log WordPress plugin before 2.8.8 retrieves client IP addresses from potentially...
Moderate
Unreviewed
CVE-2023-4281
was published
Sep 25, 2023
The User Access Manager WordPress plugin before 2.2.18 prioritizes getting a visitor's IP from...
Moderate
Unreviewed
CVE-2022-1601
was published
Aug 30, 2023
The foundry campaigns service was found to be vulnerable to an unauthenticated information...
Moderate
Unreviewed
CVE-2023-30950
was published
Aug 4, 2023
PAX Technology A930 PayDroid_7.1.1_Virgo_V04.5.02_20220722 allows attackers to compile a...
Moderate
Unreviewed
CVE-2023-27199
was published
Jul 5, 2023
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend...
Moderate
Unreviewed
CVE-2023-29147
was published
Jun 30, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34158
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34160
was published
Jun 19, 2023
Vulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this...
Moderate
Unreviewed
CVE-2023-34167
was published
Jun 19, 2023
There is a traffic hijacking vulnerability in Huawei routers. Successful exploitation of this...
Moderate
Unreviewed
CVE-2022-48469
was published
Jun 16, 2023
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may...
Moderate
Unreviewed
CVE-2023-34157
was published
Jun 16, 2023
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to...
Moderate
Unreviewed
CVE-2023-0816
was published
Mar 27, 2023
ProTip!
Advisories are also available from the
GraphQL API