GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,300 advisories
Filter by severity
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia...
Moderate
Unreviewed
CVE-2022-0837
was published
Apr 5, 2022
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7...
Moderate
Unreviewed
CVE-2022-0390
was published
Apr 3, 2022
Incorrect authorization in the Asana integration's branch restriction feature in all versions of...
Moderate
Unreviewed
CVE-2022-0740
was published
Apr 5, 2022
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
Moderate
Unreviewed
CVE-2022-1224
was published
Apr 5, 2022
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing...
Moderate
Unreviewed
CVE-2022-0825
was published
Apr 5, 2022
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check...
Moderate
Unreviewed
CVE-2022-0404
was published
Apr 5, 2022
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664...
Moderate
Unreviewed
CVE-2021-38020
was published
Dec 24, 2021
Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote...
Moderate
Unreviewed
CVE-2021-38019
was published
Dec 24, 2021
Improper sanitization of incoming intent in Galaxy Store prior to version 4.5.40.5 allows local...
Moderate
Unreviewed
CVE-2022-28542
was published
Apr 12, 2022
Stormshield Endpoint Security 2.x before 2.1.2 has Incorrect Access Control.
Moderate
Unreviewed
CVE-2021-45089
was published
Dec 22, 2021
Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 10.8 prior to 14.8.5, and...
Moderate
Unreviewed
CVE-2022-1193
was published
Apr 12, 2022
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU...
Moderate
Unreviewed
CVE-2021-39991
was published
Feb 11, 2022
There is an unauthorized rewriting vulnerability with the memory access management module on ACPU...
Moderate
Unreviewed
CVE-2021-39986
was published
Feb 11, 2022
Stormshield Endpoint Security from 2.1.0 to 2.1.1 has Incorrect Access Control.
Moderate
Unreviewed
CVE-2021-45091
was published
Dec 22, 2021
IBM Business Process Manager 8.5 and 8.6 and IBM Business Automation Workflow 18.0, 19.0, 20.0...
Moderate
Unreviewed
CVE-2021-38900
was published
Dec 22, 2021
An improper access control vulnerability [CWE-284] in FortiAuthenticator HA service 6.3.2 and...
Moderate
Unreviewed
CVE-2021-36177
was published
Feb 8, 2022
Incorrect Authorization in cross-fetch
Moderate
CVE-2022-1365
was published
for
cross-fetch
(npm)
Apr 17, 2022
An issue was discovered in SysAid ITIL 20.4.74 b10. The /enduserreg endpoint is used to register...
Moderate
Unreviewed
CVE-2021-43974
was published
Jan 12, 2022
Improper access control in the Intel(R) RealSense(TM) DCM before version 20210625 may allow an...
Moderate
Unreviewed
CVE-2021-33119
was published
Feb 11, 2022
OSIsoft PI Vision 2020 versions prior to 3.5.0 could disclose information to a user with...
Moderate
Unreviewed
CVE-2020-25167
was published
Apr 19, 2022
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and...
Moderate
Unreviewed
CVE-2020-25160
was published
Apr 15, 2022
Improper access control in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in...
Moderate
Unreviewed
CVE-2021-0171
was published
Feb 11, 2022
An issue was discovered in Delta RM 1.2. The /risque/risque/workflow/reset endpoint is lacking...
Moderate
Unreviewed
CVE-2021-44836
was published
Jan 19, 2022
Sangoma Technologies Corporation Switchvox Version 102409 is affected by an information...
Moderate
Unreviewed
CVE-2021-45310
was published
Feb 15, 2022
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated...
Moderate
Unreviewed
CVE-2021-43948
was published
Feb 16, 2022
ProTip!
Advisories are also available from the
GraphQL API