GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,501 advisories
Filter by severity
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
Moderate
Unreviewed
CVE-2016-8643
was published
May 13, 2022
Moodle Improper Access Control
Moderate
CVE-2016-3729
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle External function mod_assign_save_submission does not check due dates
Moderate
CVE-2016-2159
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Improper Access Control
Moderate
CVE-2016-3733
was published
for
moodle/moodle
(Composer)
May 13, 2022
Improper Access Control in Apache CXF
Moderate
CVE-2015-5253
was published
for
org.apache.cxf:cxf-rt-rs-security-sso-saml
(Maven)
May 13, 2022
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016...
Moderate
Unreviewed
CVE-2016-3366
was published
May 13, 2022
Improper Access Control in Apache Derby
Moderate
CVE-2018-1313
was published
for
org.apache.derby:derby
(Maven)
May 13, 2022
Improper Access Control in wp-graphql
Moderate
CVE-2019-25060
was published
for
wp-graphql/wp-graphql
(Composer)
May 10, 2022
Jenkins allows Remote Users to Build Arbitrary Jobs
Moderate
CVE-2013-0330
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 5, 2022
Multiple clientless SSL VPN products that run in web browsers, including Stonesoft StoneGate;...
Moderate
Unreviewed
CVE-2009-2631
was published
May 2, 2022
Joomla! allows attackers to access cached pages
Moderate
CVE-2008-3226
was published
for
joomla/joomla-platform
(Composer)
May 1, 2022
Cross-domain vulnerability in Microsoft Internet Explorer 5.01 SP4, 6, and 7 allows remote...
Moderate
Unreviewed
CVE-2008-2947
was published
May 1, 2022
JULI logging component in Apache Tomcat does not restrict certain permissions for web applications
Moderate
CVE-2007-5342
was published
for
org.apache.tomcat:tomcat-juli
(Maven)
May 1, 2022
Alkacon OpenCMS Improper Access Control via system/workplace/views/admin/admin-main.jsp
Moderate
CVE-2006-3935
was published
for
org.opencms:opencms-core
(Maven)
May 1, 2022
Zope allows attackers to modify raw image and file data
Moderate
CVE-2000-1212
was published
for
zope
(pip)
Apr 30, 2022
The ThirstyAffiliates Affiliate Link Manager WordPress plugin before 3.10.5 lacks authorization...
Moderate
Unreviewed
CVE-2022-0634
was published
Apr 26, 2022
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1...
Moderate
Unreviewed
CVE-2022-29417
was published
Apr 26, 2022
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23...
Moderate
Unreviewed
CVE-2022-25650
was published
Apr 13, 2022
Improper access control vulnerability in S Secure prior to SMR Apr-2022 Release 1 allows physical...
Moderate
Unreviewed
CVE-2022-25831
was published
Apr 12, 2022
Improper Access Control in GitHub repository phpipam/phpipam prior to 1.4.6.
Moderate
Unreviewed
CVE-2022-1223
was published
Apr 5, 2022
Improper Access Control in GitHub repository janeczku/calibre-web prior to 0.6.16.
Moderate
Unreviewed
CVE-2022-0405
was published
Apr 4, 2022
Path traversal allows leaking out-of-bound files from Argo CD repo-server
Moderate
CVE-2022-24731
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 24, 2022
An Improper access control vulnerability in StRetailModeReceiver in Wear OS 3.0 prior to Firmware...
Moderate
Unreviewed
CVE-2022-24930
was published
Mar 11, 2022
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23...
Moderate
Unreviewed
CVE-2022-26317
was published
Mar 9, 2022
ProTip!
Advisories are also available from the
GraphQL API