GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
295 advisories
Filter by severity
An issue was discovered in the Hyundai Gen5W_L in-vehicle infotainment system AE_E_PE_EUR...
High
Unreviewed
CVE-2023-26243
was published
Apr 27, 2023
org.xwiki.platform:xwiki-platform-oldcore vulnerable to data leak through deleted documents
High
CVE-2023-29208
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 12, 2023
Aten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to...
High
Unreviewed
CVE-2023-25409
was published
Apr 11, 2023
In telecom service, there is a missing permission check. This could lead to local denial of...
High
Unreviewed
CVE-2022-47338
was published
Apr 11, 2023
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to...
High
Unreviewed
CVE-2023-26588
was published
Apr 11, 2023
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0,...
High
Unreviewed
CVE-2023-26458
was published
Apr 11, 2023
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could...
High
Unreviewed
CVE-2022-4224
was published
Mar 23, 2023
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15...
High
Unreviewed
CVE-2023-22892
was published
Mar 8, 2023
ecdh vulnerable to Exposure of Resource to Wrong Sphere
High
CVE-2022-44310
was published
for
ecdh
(npm)
Feb 24, 2023
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating...
High
Unreviewed
CVE-2023-26081
was published
Feb 20, 2023
An attacker authenticated as a non-admin user with local access to a server port assigned to the...
High
Unreviewed
CVE-2023-24523
was published
Feb 14, 2023
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs ...
High
Unreviewed
CVE-2022-34387
was published
Feb 11, 2023
Improper access control vulnerability in MyFiles prior to versions 12.2.09 in Android R(11), 13.1...
High
Unreviewed
CVE-2023-21445
was published
Feb 9, 2023
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
High
Unreviewed
CVE-2022-47717
was published
Feb 1, 2023
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote...
High
Unreviewed
CVE-2022-22732
was published
Jan 31, 2023
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure...
High
Unreviewed
CVE-2021-41988
was published
Jan 26, 2023
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure...
High
Unreviewed
CVE-2021-41989
was published
Jan 26, 2023
An improper access control vulnerability was identified in the Realtek audio driver. A local...
High
Unreviewed
CVE-2022-34405
was published
Jan 26, 2023
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005...
High
Unreviewed
CVE-2023-21611
was published
Jan 18, 2023
Dell command configuration, version 4.8 and prior, contains improper folder permission when...
High
Unreviewed
CVE-2022-34457
was published
Jan 18, 2023
A vulnerability was found in centic9 jgit-cookbook. It has been declared as problematic. This...
High
Unreviewed
CVE-2022-4817
was published
Dec 28, 2022
robbert229/jwt's token validation methods vulnerable to a timing side-channel during HMAC comparison
High
CVE-2015-10004
was published
for
github.com/robbert229/jwt
(Go)
Dec 28, 2022
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive...
High
Unreviewed
CVE-2022-42953
was published
Dec 25, 2022
If a Thunderbird user quoted from an HTML email, for example by replying to the email, and the...
High
Unreviewed
CVE-2022-45414
was published
Dec 22, 2022
"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
High
CVE-2022-47411
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
ProTip!
Advisories are also available from the
GraphQL API