GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
322 advisories
Filter by severity
An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is...
Critical
Unreviewed
CVE-2022-47544
was published
Jan 5, 2023
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code>...
Critical
Unreviewed
CVE-2022-26384
was published
Dec 22, 2022
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently...
Critical
Unreviewed
CVE-2022-22759
was published
Dec 22, 2022
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly...
High
Unreviewed
CVE-2022-22761
was published
Dec 22, 2022
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection...
Critical
Unreviewed
CVE-2021-27497
was published
Apr 3, 2022
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is...
High
Unreviewed
CVE-2021-32960
was published
Apr 3, 2022
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding...
High
Unreviewed
CVE-2017-2685
was published
May 13, 2022
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations...
High
Unreviewed
CVE-2017-10952
was published
May 13, 2022
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD...
Critical
Unreviewed
CVE-2017-8864
was published
May 17, 2022
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2...
High
Unreviewed
CVE-2022-42848
was published
Dec 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2,...
Moderate
Unreviewed
CVE-2022-46698
was published
Dec 15, 2022
In various functions of ap_input_processor.c, there is a possible way to record audio during a...
Low
Unreviewed
CVE-2022-20562
was published
Dec 21, 2022
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2,...
Moderate
Unreviewed
CVE-2022-42821
was published
Dec 15, 2022
A logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1...
High
Unreviewed
CVE-2022-42801
was published
Nov 2, 2022
uTLS ServerHellos are accepted without checking TLS 1.3 downgrade canaries
Moderate
GHSA-pmc3-p9hx-jq96
was published
for
github.com/refraction-networking/utls
(Go)
Apr 23, 2025
Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format...
Moderate
Unreviewed
CVE-2024-29510
was published
Jul 3, 2024
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.
Moderate
Unreviewed
CVE-2021-31608
was published
Nov 18, 2022
@misskey-dev/summaly Redirect Filter Bypass
Low
CVE-2025-46553
was published
for
@misskey-dev/summaly
(npm)
May 5, 2025
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7...
High
Unreviewed
CVE-2013-2465
was published
May 14, 2022
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8,...
High
Unreviewed
CVE-2022-32910
was published
Nov 2, 2022
In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any...
High
Unreviewed
CVE-2024-25744
was published
Feb 12, 2024
The use of `module.constructor.createRequire()` can bypass the policy mechanism and require...
High
Unreviewed
CVE-2023-32006
was published
Aug 15, 2023
Jenkins NUnit Plugin vulnerable to Protection Mechanism Failure
Moderate
CVE-2022-43414
was published
for
org.jenkins-ci.plugins:nunit
(Maven)
Oct 19, 2022
Agent-to-controller security bypass vulnerability in Jenkins BMC Compuware Source Code Download for Endevor, PDS, and ISPW Plugin
Moderate
CVE-2022-43423
was published
for
com.compuware.jenkins:compuware-scm-downloader
(Maven)
Oct 19, 2022
Jenkins Compuware Topaz for Total Test Plugin vulnerable to Protection Mechanism Failure
High
CVE-2022-43429
was published
for
com.compuware.jenkins:compuware-topaz-for-total-test
(Maven)
Oct 19, 2022
ProTip!
Advisories are also available from the
GraphQL API