GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,428 advisories
Filter by severity
Prototype Pollution in node-forge util.setPath API
Low
GHSA-wxgw-qj99-44c2
was published
for
node-forge
(npm)
Jan 8, 2022
Prototype Pollution in node-forge debug API.
Low
GHSA-5rrq-pxf6-6jx5
was published
for
node-forge
(npm)
Jan 8, 2022
Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging...
Low
Unreviewed
CVE-2022-22283
was published
Jan 11, 2022
Improper authorization in TelephonyManager prior to SMR Jan-2022 Release 1 allows attackers to...
Low
Unreviewed
CVE-2022-22272
was published
Jan 11, 2022
Keeping sensitive data in unprotected BluetoothSettingsProvider prior to SMR Jan-2022 Release 1...
Low
Unreviewed
CVE-2022-22269
was published
Jan 11, 2022
Implicit Intent hijacking vulnerability in ActivityMetricsLogger prior to SMR Jan-2022 Release 1...
Low
Unreviewed
CVE-2022-22267
was published
Jan 11, 2022
(Applicable to China models only) Unprotected WifiEvaluationService in TencentWifiSecurity...
Low
Unreviewed
CVE-2022-22266
was published
Jan 11, 2022
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability. This CVE ID is unique from...
Low
Unreviewed
CVE-2022-21929
was published
Jan 12, 2022
All versions of Samba prior to 4.13.16 are vulnerable to a malicious client using an SMB1 or NFS...
Low
Unreviewed
CVE-2021-43566
was published
Jan 12, 2022
Password stored in plain text by Jenkins Publish Over SSH Plugin
Low
CVE-2022-23114
was published
for
org.jenkins-ci.plugins:publish-over-ssh
(Maven)
Jan 13, 2022
In StatusBar.java, there is a possible disclosure of notification content on the lockscreen due...
Low
Unreviewed
CVE-2021-39628
was published
Jan 15, 2022
Jimoty App for Android versions prior to 3.7.42 uses a hard-coded API key for an external service...
Low
Unreviewed
CVE-2022-0131
was published
Jan 18, 2022
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated...
Low
Unreviewed
CVE-2021-41808
was published
Jan 19, 2022
Vulnerability in the Oracle Communications Pricing Design Center product of Oracle Communications...
Low
Unreviewed
CVE-2022-21388
was published
Jan 20, 2022
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security:...
Low
Unreviewed
CVE-2022-21372
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21357
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21355
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21331
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21333
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21325
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21323
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21324
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21321
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21319
was published
Jan 20, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Low
Unreviewed
CVE-2022-21317
was published
Jan 20, 2022
ProTip!
Advisories are also available from the
GraphQL API