GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension...
High
Unreviewed
CVE-2022-24128
was published
Mar 14, 2022
IBM Data Virtualization on Cloud Pak for Data 1.3.0, 1.4.1, 1.5.0, 1.7.1 and 1.7.3 could allow an...
Moderate
Unreviewed
CVE-2021-38971
was published
Mar 15, 2022
Improper Authorization in org.cometd.oort
High
CVE-2022-24721
was published
for
org.cometd.java:cometd-java-oort
(Maven)
Mar 15, 2022
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Critical
Unreviewed
CVE-2022-26501
was published
Mar 18, 2022
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed...
High
Unreviewed
CVE-2022-25364
was published
Mar 18, 2022
Information Exposure in Apache Tapestry
High
CVE-2021-30638
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Mar 18, 2022
Permissions bypass in SmallRye
Moderate
CVE-2020-1729
was published
for
io.smallrye.config:smallrye-config
(Maven)
Mar 18, 2022
This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and...
High
Unreviewed
CVE-2022-22618
was published
Mar 19, 2022
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF...
High
Unreviewed
CVE-2021-24905
was published
Mar 22, 2022
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one...
High
Unreviewed
CVE-2022-0981
was published
Mar 24, 2022
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all...
High
Unreviewed
CVE-2021-27474
was published
Mar 24, 2022
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen...
Critical
Unreviewed
CVE-2022-26629
was published
Mar 25, 2022
An improper authorization handling flaw was found in Foreman. The OpenSCAP plugin for the smart...
Moderate
Unreviewed
CVE-2021-20290
was published
Mar 26, 2022
EyouCMS v1.5.5 was discovered to have no access control in the component /data/sqldata.
Critical
Unreviewed
CVE-2022-26279
was published
Mar 26, 2022
Incorrect Authorization in imgcrypt
High
CVE-2022-24778
was published
for
github.com/containerd/imgcrypt
(Go)
Mar 28, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14...
Critical
Unreviewed
CVE-2022-0735
was published
Mar 29, 2022
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing...
Moderate
Unreviewed
CVE-2022-0720
was published
Mar 29, 2022
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee...
Moderate
Unreviewed
CVE-2021-39876
was published
Mar 29, 2022
Sandbox bypass leading to arbitrary code execution in Deno
Critical
CVE-2022-24783
was published
for
deno
(Rust)
Mar 29, 2022
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy...
High
Unreviewed
CVE-2021-3456
was published
Mar 31, 2022
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing...
High
Unreviewed
CVE-2021-39790
was published
Mar 31, 2022
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission...
High
Unreviewed
CVE-2022-20002
was published
Mar 31, 2022
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This...
High
Unreviewed
CVE-2021-39789
was published
Mar 31, 2022
In PackageManager, there is a possible way to change the splash screen theme of other apps due to...
High
Unreviewed
CVE-2021-39750
was published
Mar 31, 2022
In Settings, there is a possible way to read Bluetooth device names without proper permissions...
Moderate
Unreviewed
CVE-2021-39751
was published
Mar 31, 2022
ProTip!
Advisories are also available from the
GraphQL API