GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
666 advisories
Filter by severity
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Moderate
CVE-2024-38827
was published
for
org.springframework.security:spring-security-core
(Maven)
Dec 2, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
Critical
Unreviewed
CVE-2024-1626
was published
Apr 16, 2024
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged...
High
Unreviewed
CVE-2024-4154
was published
May 21, 2024
An Improper Access Control vulnerability exists in lunary-ai/lunary version 1.2.2, where users...
High
Unreviewed
CVE-2024-4151
was published
May 20, 2024
The WPBookit plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up...
Critical
Unreviewed
CVE-2024-10215
was published
Jan 9, 2025
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Insecure Direct...
Moderate
Unreviewed
CVE-2024-1289
was published
Apr 9, 2024
An Insecure Direct Object Reference (IDOR) vulnerability exists in the lunary-ai/lunary...
High
Unreviewed
CVE-2024-1625
was published
Apr 10, 2024
Multiple functions are vulnerable to Authorization Bypass in AIMS eCrew. The issue was fixed in...
Moderate
Unreviewed
CVE-2024-44450
was published
Jan 7, 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for...
Moderate
Unreviewed
CVE-2024-12131
was published
Jan 7, 2025
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for...
Moderate
Unreviewed
CVE-2024-12132
was published
Jan 3, 2025
The QOCA aim from Quanta Computer has an Authorization Bypass Through User-Controlled Key...
High
Unreviewed
CVE-2024-13040
was published
Dec 31, 2024
TeamPass privileges issue
Critical
CVE-2024-50703
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
khoj has an IDOR in subscription management allows unauthorized subscription modifications
Moderate
CVE-2024-52294
was published
for
khoj
(pip)
Dec 30, 2024
An IDOR vulnerability in the edit-notes.php module of PHPGurukul Online Notes Sharing Management...
Moderate
Unreviewed
CVE-2024-55231
was published
Dec 19, 2024
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates)...
High
Unreviewed
CVE-2024-55506
was published
Dec 19, 2024
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all...
Moderate
Unreviewed
CVE-2024-12335
was published
Dec 25, 2024
The Content No Cache: prevent specific content from being cached plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12103
was published
Dec 24, 2024
The Full Screen Menu for Elementor plugin for WordPress is vulnerable to Information Exposure in...
Moderate
Unreviewed
CVE-2024-10797
was published
Dec 21, 2024
Oqtane Framework Insecure Direct Object Reference vulnerability
Low
CVE-2024-55186
was published
for
Oqtane.Client
(NuGet)
Dec 20, 2024
Oqtane Framework Insecure Direct Object Reference vulnerability
Moderate
CVE-2024-55471
was published
for
Oqtane.Framework
(NuGet)
Dec 20, 2024
Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer...
Low
Unreviewed
CVE-2024-12014
was published
Dec 20, 2024
In checkKeyIntentParceledCorrectly() of ActivityManagerService.java, there is a possible bypass...
High
Unreviewed
CVE-2023-21131
was published
Jun 15, 2023
Authorization bypass through user-controlled key vulnerability in streaming service in Synology...
High
Unreviewed
CVE-2024-4464
was published
Dec 18, 2024
The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all...
Moderate
Unreviewed
CVE-2024-12061
was published
Dec 18, 2024
Authorization Bypass Through User-Controlled Key vulnerability in NextGeography NG Analyser...
Moderate
Unreviewed
CVE-2024-9819
was published
Dec 17, 2024
ProTip!
Advisories are also available from the
GraphQL API