GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,586 advisories
Filter by severity
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain...
Low
Unreviewed
CVE-2023-44298
was published
Dec 5, 2023
An issue exists in SoftIron HyperCloud where compute nodes may come online immediately without...
Low
Unreviewed
CVE-2023-45085
was published
Dec 5, 2023
Canonical LXD documentation improvement to make clear restricted.devices.disk=allow without restricted.devices.disk.paths also allows shift=true
Low
GHSA-x9qq-236j-gj97
was published
for
github.com/canonical/lxd
(Go)
Dec 5, 2023
PyDrive2's unsafe YAML deserialization in LoadSettingsFile allows arbitrary code execution
Low
CVE-2023-49297
was published
for
PyDrive2
(pip)
Dec 5, 2023
eventing-github vulnerable to denial of service caused by improper enforcement of the timeout on individual read operations
Low
GHSA-v7hc-87jc-qrrr
was published
for
knative.dev/eventing-github
(Go)
Dec 6, 2023
Microweber missing standardized error handling mechanism
Low
CVE-2023-6599
was published
for
microweber/microweber
(Composer)
Dec 8, 2023
dbt-core's secret env vars written to package-lock.json in plaintext
Low
GHSA-j4g3-3q8x-jxqp
was published
for
dbt-core
(pip)
Dec 8, 2023
A vulnerability classified as problematic was found in Typecho 1.2.1. Affected by this...
Low
Unreviewed
CVE-2023-6614
was published
Dec 8, 2023
A vulnerability classified as problematic has been found in Typecho 1.2.1. Affected is an unknown...
Low
Unreviewed
CVE-2023-6613
was published
Dec 8, 2023
A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected...
Low
Unreviewed
CVE-2023-6615
was published
Dec 8, 2023
eventing-gitlab vulnerable to denial of service, caused by improper enforcement of the timeout on individual read operations
Low
GHSA-99jv-8292-2hpm
was published
for
knative.dev/eventing-gitlab
(Go)
Dec 8, 2023
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background...
Low
Unreviewed
CVE-2023-5870
was published
Dec 10, 2023
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered...
Low
Unreviewed
CVE-2023-6194
was published
Dec 11, 2023
Stale copy of the public suffix list
Low
GHSA-w4x6-hh3x-wjrx
was published
for
Gsemac.Net
(NuGet)
Dec 11, 2023
This issue was addressed with improved state management. This issue is fixed in macOS Sonoma 14.2...
Low
Unreviewed
CVE-2023-42874
was published
Dec 12, 2023
SAP Master Data Governance File Upload application allows an attacker to exploit insufficient...
Low
Unreviewed
CVE-2023-49058
was published
Dec 12, 2023
SAP Cloud Connector - version 2.0, allows an authenticated user with low privilege to perform...
Low
Unreviewed
CVE-2023-49578
was published
Dec 12, 2023
Mattermost fails to validate team membership when a user attempts to access a playbook, allowing...
Low
Unreviewed
CVE-2023-6547
was published
Dec 12, 2023
Mattermost fails to perform correct authorization checks when creating a playbook action,...
Low
Unreviewed
CVE-2023-6727
was published
Dec 12, 2023
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The Web UI...
Low
Unreviewed
CVE-2023-48429
was published
Dec 12, 2023
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The REST API...
Low
Unreviewed
CVE-2023-48430
was published
Dec 12, 2023
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious...
Low
Unreviewed
CVE-2023-6710
was published
Dec 13, 2023
An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and...
Low
Unreviewed
CVE-2023-47536
was published
Dec 13, 2023
An improper neutralization of input during web page generation ('cross-site scripting') in...
Low
Unreviewed
CVE-2023-45587
was published
Dec 13, 2023
A improper neutralization of input during web page generation ('cross-site scripting') in...
Low
Unreviewed
CVE-2023-41844
was published
Dec 13, 2023
ProTip!
Advisories are also available from the
GraphQL API