GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
136 advisories
Filter by severity
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation...
High
Unreviewed
CVE-2022-4106
was published
Dec 19, 2022
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https:...
High
Unreviewed
CVE-2022-45227
was published
Dec 12, 2022
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030...
High
Unreviewed
CVE-2022-44356
was published
Nov 29, 2022
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive...
High
Unreviewed
CVE-2022-3691
was published
Nov 21, 2022
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
High
Unreviewed
CVE-2022-44583
was published
Nov 19, 2022
There is a file inclusion vulnerability in the template management module in UCMS 1.6
High
Unreviewed
CVE-2022-42234
was published
Oct 14, 2022
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows...
High
Unreviewed
CVE-2022-40126
was published
Sep 30, 2022
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi...
High
Unreviewed
CVE-2022-36552
was published
Aug 31, 2022
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how...
High
Unreviewed
CVE-2022-1117
was published
Aug 29, 2022
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation...
High
Unreviewed
CVE-2021-4112
was published
Aug 26, 2022
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak...
High
Unreviewed
CVE-2021-3800
was published
Aug 24, 2022
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file...
High
Unreviewed
CVE-2022-2357
was published
Aug 9, 2022
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup...
High
Unreviewed
CVE-2022-1585
was published
Aug 2, 2022
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some...
High
Unreviewed
CVE-2022-33158
was published
Jul 31, 2022
Unauthenticated Arbitrary File Read vulnerability in MultiSafepay plugin for WooCommerce plugin <...
High
Unreviewed
CVE-2022-33901
was published
Jul 23, 2022
The web server of the E1 Zoom camera through 3.0.0.716 discloses its configuration via the /conf/...
High
Unreviewed
CVE-2021-40150
was published
Jul 18, 2022
IOBit Advanced System Care (Asc.exe) 15 and Action Download Center both download components of...
High
Unreviewed
CVE-2022-24138
was published
Jul 7, 2022
In multiple CODESYS products, file download and upload function allows access to internal files...
High
Unreviewed
CVE-2022-32143
was published
Jun 25, 2022
74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component ...
High
Unreviewed
CVE-2022-29720
was published
May 27, 2022
Docker Desktop 4.3.0 has Incorrect Access Control.
High
Unreviewed
CVE-2021-44719
was published
May 26, 2022
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper...
High
Unreviewed
CVE-2021-22015
was published
May 24, 2022
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read...
High
Unreviewed
CVE-2020-35340
was published
May 24, 2022
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there...
High
Unreviewed
CVE-2021-32833
was published
May 24, 2022
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access...
High
Unreviewed
CVE-2020-22124
was published
May 24, 2022
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
High
Unreviewed
CVE-2021-38711
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API