GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,396
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
227 advisories
Filter by severity
Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates list
Moderate
CVE-2024-21666
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
Moderate
CVE-2024-21665
was published
for
pimcore/ecommerce-framework-bundle
(Composer)
Jan 10, 2024
Mattermost viewing archived public channels permissions vulnerability
Moderate
CVE-2023-47858
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Jan 2, 2024
Apache Airflow Improper Access Control vulnerability
Moderate
CVE-2023-50783
was published
for
apache-airflow
(pip)
Dec 21, 2023
Broken access control in Silverpeas
Moderate
CVE-2023-47325
was published
for
org.silverpeas.core:silverpeas-core-web
(Maven)
Dec 13, 2023
Broken access control in Silverpeas
Moderate
CVE-2023-47321
was published
for
org.silverpeas.core:silverpeas-core-web
(Maven)
Dec 13, 2023
Broken access control in Silverpeas
Moderate
CVE-2023-47327
was published
for
org.silverpeas.core:silverpeas-core-web
(Maven)
Dec 13, 2023
OroCommerce get-totals-for-checkout API endpoint returns unwanted data
Moderate
CVE-2023-32065
was published
for
oro/commerce
(Composer)
Nov 27, 2023
OroCommerce Customer Portal Incorrect Customer and Customer Group Frontend Menus pages visibility
Moderate
CVE-2023-32064
was published
for
oro/customer-portal
(Composer)
Nov 27, 2023
OroCRMCallBundle has incorrect call view page visibility
Moderate
CVE-2023-32063
was published
for
oro/crm-call-bundle
(Composer)
Nov 27, 2023
OroCalendarBundle has incorrect system calendar events visibility
Moderate
CVE-2023-32062
was published
for
oro/calendar-bundle
(Composer)
Nov 27, 2023
Mattermost Improper Access Control vulnerability
Moderate
CVE-2023-6202
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Nov 27, 2023
Mattermost Improper Access Control vulnerability
Moderate
CVE-2023-47865
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Nov 27, 2023
Microweber Improper Access Control vulnerability
Moderate
CVE-2023-5976
was published
for
microweber/microweber
(Composer)
Nov 14, 2023
Moodle Improper Access Control vulnerability
Moderate
CVE-2023-5549
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
Moodle Improper Access Control vulnerability
Moderate
CVE-2023-5542
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
Any value can be changed in the configuration table by an employee having access to block reassurance module
Moderate
CVE-2023-47110
was published
for
prestashop/blockreassurance
(Composer)
Nov 9, 2023
Improper Access Control in vantage6
Moderate
CVE-2023-41882
was published
for
vantage6
(pip)
Oct 13, 2023
io.micronaut.security:micronaut-security-oauth2 has invalid IdTokenClaimsValidator logic on aud
Moderate
CVE-2023-36820
was published
for
io.micronaut.security:micronaut-security-oauth2
(Maven)
Oct 5, 2023
cross-site inclusion (XSSI) of files in jupyter-server
Moderate
CVE-2023-40170
was published
for
jupyter-server
(pip)
Aug 29, 2023
OpenFGA Authorization Bypass
Moderate
CVE-2023-40579
was published
for
github.com/openfga/openfga
(Go)
Aug 25, 2023
Mattermost fails to check if user is a guest before performing actions on public playbooks
Moderate
CVE-2023-4106
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Mattermost does not validate requesting user permissions before updating admin details
Moderate
CVE-2023-4107
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Aug 11, 2023
Easy!Appointments Improper Access Control vulnerability
Moderate
CVE-2023-3700
was published
for
alextselegidis/easyappointments
(Composer)
Jul 17, 2023
PlantUML Improper Access Control vulnerability
Moderate
CVE-2023-3431
was published
for
net.sourceforge.plantuml:plantuml-mit
(Maven)
Jun 27, 2023
ProTip!
Advisories are also available from the
GraphQL API