GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
291 advisories
Filter by severity
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to...
High
Unreviewed
CVE-2023-25409
was published
Apr 11, 2023
In telecom service, there is a missing permission check. This could lead to local denial of...
High
Unreviewed
CVE-2022-47338
was published
Apr 11, 2023
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to...
High
Unreviewed
CVE-2023-26588
was published
Apr 11, 2023
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0,...
High
Unreviewed
CVE-2023-26458
was published
Apr 11, 2023
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could...
High
Unreviewed
CVE-2022-4224
was published
Mar 23, 2023
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15...
High
Unreviewed
CVE-2023-22892
was published
Mar 8, 2023
ecdh vulnerable to Exposure of Resource to Wrong Sphere
High
CVE-2022-44310
was published
for
ecdh
(npm)
Feb 24, 2023
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating...
High
Unreviewed
CVE-2023-26081
was published
Feb 20, 2023
An attacker authenticated as a non-admin user with local access to a server port assigned to the...
High
Unreviewed
CVE-2023-24523
was published
Feb 14, 2023
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs ...
High
Unreviewed
CVE-2022-34387
was published
Feb 11, 2023
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1...
High
Unreviewed
CVE-2023-21445
was published
Feb 9, 2023
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
High
Unreviewed
CVE-2022-47717
was published
Feb 1, 2023
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote...
High
Unreviewed
CVE-2022-22732
was published
Jan 31, 2023
An improper access control vulnerability was identified in the Realtek audio driver. A local...
High
Unreviewed
CVE-2022-34405
was published
Jan 26, 2023
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005...
High
Unreviewed
CVE-2023-21611
was published
Jan 18, 2023
Dell command configuration, version 4.8 and prior, contains improper folder permission when...
High
Unreviewed
CVE-2022-34457
was published
Jan 18, 2023
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This...
High
Unreviewed
CVE-2022-4817
was published
Dec 28, 2022
robbert229/jwt's token validation methods vulnerable to a timing side-channel during HMAC comparison
High
CVE-2015-10004
was published
for
github.com/robbert229/jwt
(Go)
Dec 28, 2022
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive...
High
Unreviewed
CVE-2022-42953
was published
Dec 25, 2022
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the...
High
Unreviewed
CVE-2022-45414
was published
Dec 22, 2022
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension...
High
Unreviewed
CVE-2022-47411
was published
Dec 14, 2022
An issue was discovered in the fp_newsletter (aka Newsletter subscriber management) extension...
High
Unreviewed
CVE-2022-47410
was published
Dec 14, 2022
Exposure of Sensitive System Information to an Unauthorized Control Sphere in GitHub repository...
High
Unreviewed
CVE-2022-4366
was published
Dec 8, 2022
HTSJDK is vulnerable to exposure of resource(s) to the wrong sphere
High
CVE-2022-21126
was published
for
com.github.samtools:htsjdk
(Maven)
Nov 29, 2022
PHPGurukul Blood Donor Management System 1.0 does not properly restrict access to admin/dashboard...
High
Unreviewed
CVE-2022-38813
was published
Nov 25, 2022
ProTip!
Advisories are also available from the
GraphQL API