GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
277 advisories
Filter by severity
Improper Privilege Management in github.com/sap/cloud-security-client-go
Critical
CVE-2023-50424
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 13, 2023
Improper JWT Signature Validation in SAP Security Services Library
Critical
CVE-2023-50422
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 13, 2023
Duplicate Advisory: Improper JWT Signature Validation in SAP Security Services Library
Critical
GHSA-gcgw-q47m-prvj
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Privilege escalation in sap/cloud-security-client-go
Critical
GHSA-92cg-ghq6-9587
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Privilege escalation in sap-xssec
Critical
GHSA-p99h-pfg6-qrfg
was published
for
sap-xssec
(pip)
Dec 12, 2023
•
withdrawn
Escalation of privileges in @sap/xssec
Critical
CVE-2023-49583
was published
for
@sap/xssec
(npm)
Dec 12, 2023
Improper Privilege Management vulnerability in Pandora FMS on all allows Privilege Escalation....
Critical
Unreviewed
CVE-2023-41807
was published
Nov 23, 2023
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older...
Critical
Unreviewed
CVE-2023-39335
was published
Nov 15, 2023
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an...
Critical
Unreviewed
CVE-2023-31273
was published
Nov 14, 2023
A vulnerability in the web services interface of Cisco Firepower Management Center (FMC) Software...
Critical
Unreviewed
CVE-2023-20048
was published
Nov 1, 2023
D-Link device DIR-820L 1.05B03 is vulnerable to Insecure Permissions.
Critical
Unreviewed
CVE-2023-44809
was published
Oct 16, 2023
Vulnerability of permissions not being strictly verified in the window management module...
Critical
Unreviewed
CVE-2023-44105
was published
Oct 11, 2023
API permission management vulnerability in the Fwk-Display module.Successful exploitation of this...
Critical
Unreviewed
CVE-2023-44106
was published
Oct 11, 2023
Puppet Bolt privilege escalation vulnerability
Critical
CVE-2023-5214
was published
for
bolt
(RubyGems)
Oct 6, 2023
A?CWE-269: Improper Privilege Management vulnerability exists?that could cause?a local privilege...
Critical
Unreviewed
CVE-2023-5402
was published
Oct 4, 2023
SiberianCMS - CWE-274: Improper Handling of Insufficient Privileges
Critical
Unreviewed
CVE-2023-39375
was published
Sep 27, 2023
An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges...
Critical
Unreviewed
CVE-2023-43457
was published
Sep 25, 2023
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code...
Critical
Unreviewed
CVE-2023-4662
was published
Sep 15, 2023
An issue was discovered in OPSWAT MetaDefender KIOSK 4.6.1.9996. Built-in features of Windows ...
Critical
Unreviewed
CVE-2023-36657
was published
Sep 15, 2023
An issue was discovered in IceCMS version 2.0.1, allows attackers to escalate privileges and gain...
Critical
Unreviewed
CVE-2023-36100
was published
Sep 1, 2023
An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering...
Critical
Unreviewed
CVE-2023-31175
was published
Aug 31, 2023
Inappropriate implementation in OS in Google Chrome on ChromeOS prior to 75.0.3770.80 allowed a...
Critical
Unreviewed
CVE-2019-13690
was published
Aug 25, 2023
The Donation Forms by Charitable plugin for WordPress is vulnerable to privilege escalation in...
Critical
Unreviewed
CVE-2023-4404
was published
Aug 23, 2023
IBM Robotic Process Automation 21.0.0 through 21.0.7.1 and 23.0.0 through 23.0.1 is vulnerable...
Critical
Unreviewed
CVE-2023-38734
was published
Aug 23, 2023
An issue was discovered in getRememberedSerializedIdentity function in CookieRememberMeManager...
Critical
Unreviewed
CVE-2021-28411
was published
Aug 11, 2023
ProTip!
Advisories are also available from the
GraphQL API