GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,509
Maven
5,000+
npm
4,149
NuGet
736
pip
3,949
Pub
12
RubyGems
946
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
325 advisories
Filter by severity
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered...
High
Unreviewed
CVE-2023-3089
was published
Jul 5, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2021-31982
was published
Jul 1, 2023
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All...
Moderate
Unreviewed
CVE-2023-30757
was published
Jun 13, 2023
Potential HTTP policy bypass when using header rules in Cilium
Moderate
CVE-2023-30851
was published
for
github.com/cilium/cilium
(Go)
May 22, 2023
Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an...
High
Unreviewed
CVE-2022-41979
was published
May 10, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-29354
was published
May 6, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-28286
was published
Apr 27, 2023
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2023-28284
was published
Apr 11, 2023
In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic...
High
Unreviewed
CVE-2023-21024
was published
Mar 24, 2023
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass...
Moderate
Unreviewed
CVE-2023-0085
was published
Mar 2, 2023
Sandbox escape in Jenkins Email Extension Plugin
Critical
CVE-2023-25765
was published
for
org.jenkins-ci.plugins:email-ext
(Maven)
Feb 15, 2023
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of...
Critical
Unreviewed
CVE-2022-48290
was published
Feb 9, 2023
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this...
High
Unreviewed
CVE-2022-48287
was published
Feb 9, 2023
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation...
High
Unreviewed
CVE-2023-20919
was published
Jan 26, 2023
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol...
Moderate
Unreviewed
CVE-2023-23589
was published
Jan 14, 2023
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid...
Moderate
Unreviewed
CVE-2021-26355
was published
Jan 11, 2023
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed...
Moderate
Unreviewed
CVE-2023-0131
was published
Jan 10, 2023
Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote...
Moderate
Unreviewed
CVE-2023-0141
was published
Jan 10, 2023
The memory management module has a logic bypass vulnerability.Successful exploitation of this...
High
Unreviewed
CVE-2022-46762
was published
Jan 6, 2023
An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is...
Critical
Unreviewed
CVE-2022-47544
was published
Jan 5, 2023
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly...
High
Unreviewed
CVE-2022-22761
was published
Dec 22, 2022
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code>...
Critical
Unreviewed
CVE-2022-26384
was published
Dec 22, 2022
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently...
Critical
Unreviewed
CVE-2022-22759
was published
Dec 22, 2022
In various functions of ap_input_processor.c, there is a possible way to record audio during a...
Low
Unreviewed
CVE-2022-20562
was published
Dec 21, 2022
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2,...
Moderate
Unreviewed
CVE-2022-46698
was published
Dec 15, 2022
ProTip!
Advisories are also available from the
GraphQL API