GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,047
Maven
5,000+
npm
3,739
NuGet
668
pip
3,415
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
48 advisories
Filter by severity
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not...
Critical
Unreviewed
CVE-2022-27919
was published
Mar 26, 2022
In Weidmüller u-controls and IoT-Gateways in versions up to 1.12.1 a network port intended only...
Critical
Unreviewed
CVE-2021-20999
was published
May 24, 2022
Windows OS can be configured to overlay a “language bar” on top of any application. When this OS...
Critical
Unreviewed
CVE-2022-1467
was published
May 24, 2022
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product...
Critical
Unreviewed
CVE-2021-35211
was published
May 24, 2022
Dell PowerStore versions 2.0.0.x, 2.0.1.x and 2.1.0.x contains an open port vulnerability. A...
Critical
Unreviewed
CVE-2022-26869
was published
Jun 3, 2022
Improper control of program execution vulnerability in RevoWorks Browser 2.1.230 and earlier...
Critical
Unreviewed
CVE-2021-20790
was published
May 24, 2022
IBM API Connect 5.0.0.0 through 5.0.8.11 could alllow a remote user to obtain sensitive...
Critical
Unreviewed
CVE-2021-29715
was published
May 24, 2022
An issue was discovered in Couchbase Server before 7.0.4. Random HTTP requests lead to leaked...
Critical
Unreviewed
CVE-2022-32559
was published
Jun 15, 2022
Fast Food Ordering System v1.0 is vulnerable to Delete any file. via /ffos/classes/Master.php?f...
Critical
Unreviewed
CVE-2022-32328
was published
Jun 15, 2022
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary...
Critical
Unreviewed
CVE-2013-4561
was published
Jul 1, 2022
A network misconfiguration is present in versions prior to 1.0.9.90 of the NETGEAR RAX30 AX2400...
Critical
Unreviewed
CVE-2022-4390
was published
Dec 9, 2022
xmlparse.c in Expat (aka libexpat) before 2.4.5 allows attackers to insert namespace-separator...
Critical
Unreviewed
CVE-2022-25236
was published
Feb 17, 2022
A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all...
Critical
Unreviewed
CVE-2018-7846
was published
May 24, 2022
Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows...
Critical
Unreviewed
CVE-2020-16263
was published
May 24, 2022
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows...
Critical
Unreviewed
CVE-2021-27236
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** ThinkUp 2.0-beta.10 is affected by a path manipulation...
Critical
Unreviewed
CVE-2021-43674
was published
Dec 4, 2021
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
Critical
Unreviewed
CVE-2021-30190
was published
May 24, 2022
An access control issue in Zammad v5.0.3 allows attackers to write entries to the CTI caller log...
Critical
Unreviewed
CVE-2022-27332
was published
Apr 28, 2022
An improper access control vulnerability in GitHub Enterprise Server allowed a workflow job to...
Critical
Unreviewed
CVE-2021-22869
was published
May 24, 2022
Improper Access Control vulnerability in the patchesUpdate API as implemented in Bitdefender...
Critical
Unreviewed
CVE-2021-3554
was published
May 24, 2022
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead...
Critical
Unreviewed
CVE-2021-42001
was published
May 3, 2022
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated...
Critical
Unreviewed
CVE-2021-44523
was published
Dec 15, 2021
A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated...
Critical
Unreviewed
CVE-2021-44524
was published
Dec 15, 2021
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations...
Critical
Unreviewed
CVE-2017-16597
was published
May 13, 2022
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations...
Critical
Unreviewed
CVE-2017-16610
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API