GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            172 advisories
        Filter by severity
        
      
      
    
                    
                      Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-35255
                      
                      was published
                        for
                        
                          @azure/identity
                        
                        (Go)
                      Jun 11, 2024 
                    
                  
                    
                      Grafana Race condition allowing privilege escalation
                    
                      
  Critical
                    
                
                      
                        CVE-2022-39328
                      
                      was published
                        for
                        
                          github.com/grafana/grafana
                        
                        (Go)
                      May 14, 2024 
                    
                  
                    
                      Microsoft Security Advisory CVE-2024-30046 | .NET Denial of Service Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-30046
                      
                      was published
                        for
                        
                          Microsoft.AspNetCore.App.Runtime.linux-arm
                        
                        (NuGet)
                      May 14, 2024 
                    
                  
                    
                      WordOps has TOCTOU race condition
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-34528
                      
                      was published
                        for
                        
                          wordops
                        
                        (pip)
                      May 6, 2024 
                    
                  
                    
                      Pterodactyl Wings vulnerable to improper isolation of server file access
                    
                      
  Critical
                    
                
                      
                        CVE-2024-27102
                      
                      was published
                        for
                        
                          github.com/pterodactyl/wings
                        
                        (Go)
                      Mar 15, 2024 
                    
                  
                    
                      vantage6 vulnerable to a username timing attack on recover password/MFA token
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-24770
                      
                      was published
                        for
                        
                          vantage6
                        
                        (pip)
                      Mar 15, 2024 
                    
                  
                    
                      Mattermost race condition
                    
                      
  Low
                    
                
                      
                        CVE-2024-1949
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost/server/v8
                        
                        (Go)
                      Feb 29, 2024 
                    
                  
                    
                      Apache Answer Race Condition vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-26578
                      
                      was published
                        for
                        
                          github.com/apache/incubator-answer
                        
                        (Go)
                      Feb 22, 2024 
                    
                  
                    
                      BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts
                    
                      
  High
                    
                
                      
                        CVE-2024-23651
                      
                      was published
                        for
                        
                          github.com/moby/buildkit
                        
                        (Go)
                      Jan 31, 2024 
                    
                  
                    
                      Apache Answer Race Condition vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2023-49619
                      
                      was published
                        for
                        
                          github.com/apache/incubator-answer
                        
                        (Go)
                      Jan 10, 2024 
                    
                  
                    
                      snapd Race Condition vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2022-3328
                      
                      was published
                        for
                        
                          github.com/snapcore/snapd
                        
                        (Go)
                      Jan 8, 2024 
                    
                  
                    
                      Duplicate Advisory: Race Condition leading to logging errors
                    
                      
  Low
                    
                
                      
                        GHSA-v444-jggx-6v7f
                      
                      was published
                        for
                        
                          audited
                        
                        (RubyGems)
                      Jan 4, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      Deis Workflow Manager race condition vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-15036
                      
                      was published
                        for
                        
                          github.com/deis/workflow-manager
                        
                        (Go)
                      Dec 23, 2023 
                    
                  
                    
                      github.com/go-resty/resty/v2 HTTP request body disclosure
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-45286
                      
                      was published
                        for
                        
                          github.com/go-resty/resty/v2
                        
                        (Go)
                      Nov 28, 2023 
                    
                  
                    
                      Fabric vulnerable to crosslinking transaction attack
                    
                      
  High
                    
                
                      
                        CVE-2023-46132
                      
                      was published
                        for
                        
                          github.com/hyperledger/fabric
                        
                        (Go)
                      Nov 14, 2023 
                    
                  
                    
                      ZITADEL race condition in lockout policy execution
                    
                      
  High
                    
                
                      
                        CVE-2023-47111
                      
                      was published
                        for
                        
                          github.com/zitadel/zitadel
                        
                        (Go)
                      Nov 8, 2023 
                    
                  
                    
                      Harbor timing attack risk
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-20902
                      
                      was published
                        for
                        
                          github.com/goharbor/harbor
                        
                        (Go)
                      Oct 10, 2023 
                    
                  
                    
                       Microsoft Security Advisory CVE-2023-33170: .NET Security Feature Bypass Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2023-33170
                      
                      was published
                        for
                        
                          Microsoft.AspNet.Identity.Owin
                        
                        (NuGet)
                      Jul 11, 2023 
                    
                  
                    
                      `chainId` may be outdated if user changes chains as part of connection in @web3-react
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-30543
                      
                      was published
                        for
                        
                          @web3-react/coinbase-wallet
                        
                        (npm)
                      Apr 18, 2023 
                    
                  
                    
                      Timing attack in eZ Platform Ibexa
                    
                      
  Low
                    
                
                      
                        CVE-2022-48366
                      
                      was published
                        for
                        
                          ezsystems/ezplatform-kernel
                        
                        (Composer)
                      Mar 12, 2023 
                    
                  
                    
                      Answer vulnerable to Race Condition
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0739
                      
                      was published
                        for
                        
                          github.com/answerdev/answer
                        
                        (Go)
                      Feb 8, 2023 
                    
                  
                    
                      Deno is vulnerable to race condition via interactive permission prompt spoofing
                    
                      
  High
                    
                
                      
                        CVE-2023-22499
                      
                      was published
                        for
                        
                          deno
                        
                        (Rust)
                      Jan 20, 2023 
                    
                  
                    
                      efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-46174
                      
                      was published
                        for
                        
                          github.com/kubernetes-sigs/aws-efs-csi-driver
                        
                        (Go)
                      Dec 30, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API