GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
20 advisories
Filter by severity
usememos/memos has Insufficient Granularity of Access Control
Moderate
CVE-2022-4801
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos has Insufficient Granularity of Access Control
Moderate
CVE-2022-4813
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
Argo CD improper access control bug can allow malicious user to escalate privileges to admin level
High
CVE-2022-1025
was published
for
github.com/argoproj/argo-cd
(Go)
Jul 13, 2022
Netmaker vulnerable to Insufficient Granularity of Access Control
High
CVE-2022-36110
was published
for
github.com/gravitl/netmaker
(Go)
Sep 15, 2022
Microsoft Security Advisory CVE-2023-33127: .NET Remote Code Execution Vulnerability
High
CVE-2023-33127
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Jul 11, 2023
aimeos/ai-admin-graphql improper access control vulnerability allows an editor to modify admin account
High
CVE-2024-39323
was published
for
aimeos/ai-admin-graphql
(Composer)
Jul 2, 2024
aimeos/ai-admin-graphql improper access control vulnerability allows editors to manage own services
Low
CVE-2024-39324
was published
for
aimeos/ai-admin-graphql
(Composer)
Jul 2, 2024
Withdrawn Advisory: Insufficient Granularity of Access Control in JSDom
Low
CVE-2021-20066
was published
for
jsdom
(npm)
May 24, 2022
•
withdrawn
lunary-ai/lunary Access Control Vulnerability in Prompt Variation Management
Moderate
CVE-2024-5389
was published
for
lunary
(npm)
Jun 10, 2024
•
withdrawn
Unauthenticated Miniflux user can bypass allowed networks check to obtain Prometheus metrics
High
CVE-2023-27591
was published
for
miniflux.app
(Go)
Apr 2, 2025
Withdrawn Advisory: Lunary information disclosure vulnerability
Moderate
CVE-2024-6867
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
Kimai API returns timesheet entries a user should not be authorized to view
Moderate
CVE-2024-29200
was published
for
kimai/kimai
(Composer)
Mar 29, 2024
Paperclip: Cross-tenant agent API token minting via missing assertCompanyAccess on /api/agents/:id/keys
Critical
GHSA-47wq-cj9q-wpmp
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
OpenClaw: Agent gateway config mutations could change protected operator settings
Moderate
GHSA-7jm2-g593-4qrc
was published
for
openclaw
(npm)
Apr 25, 2026
Apache Airflow's authenticated /ui/dags endpoint did not enforce per-DAG access control on embedded Human-in-the-Loop (HITL) and TaskInstance record
Moderate
CVE-2026-38743
was published
for
apache-airflow
(pip)
Apr 24, 2026
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Moderate
CVE-2026-40690
was published
for
apache-airflow
(pip)
Apr 24, 2026
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
Critical
CVE-2026-2651
was published
for
mlflow
(pip)
May 26, 2026
Keycloak Account Resources user lookup contains broken access control
Moderate
CVE-2026-37981
was published
for
org.keycloak:keycloak-services
(Maven)
May 19, 2026
Keycloak: Information disclosure due to user profile permission bypass
Low
CVE-2026-9088
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API