GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,260 advisories
Filter by severity
A flaw was discovered in gfs2 file system’s handling of acls (access control lists). An...
High
Unreviewed
CVE-2010-2525
was published
May 13, 2022
Moxa PT-7728 devices with software 3.4 build 15081113 allow remote authenticated users to change...
High
Unreviewed
CVE-2016-4514
was published
May 13, 2022
A vulnerability in the Graphite interface of Cisco HyperFlex software could allow an...
Low
Unreviewed
CVE-2019-1667
was published
May 13, 2022
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access...
Moderate
Unreviewed
CVE-2019-3887
was published
May 13, 2022
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the...
High
Unreviewed
CVE-2019-3842
was published
May 13, 2022
The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated...
High
Unreviewed
CVE-2013-6926
was published
May 13, 2022
Insufficient Policy Enforcement in Omnibox in Google Chrome prior to 58.0.3029.81 for Mac,...
Moderate
Unreviewed
CVE-2017-5060
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in miner_setGasPrice API of cpp...
High
Unreviewed
CVE-2017-12116
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in miner_setEtherbase API of cpp...
High
Unreviewed
CVE-2017-12115
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in admin_nodeInfo API of cpp-ethereum...
High
Unreviewed
CVE-2017-12113
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in admin_peers API of cpp-ethereum's...
Moderate
Unreviewed
CVE-2017-12114
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in admin_addPeer API of cpp-ethereum's...
High
Unreviewed
CVE-2017-12112
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in miner_start API of cpp-ethereum's...
High
Unreviewed
CVE-2017-12117
was published
May 13, 2022
An exploitable improper authorization vulnerability exists in miner_stop API of cpp-ethereum's...
High
Unreviewed
CVE-2017-12118
was published
May 13, 2022
The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows...
High
Unreviewed
CVE-2022-30594
was published
May 13, 2022
RESI Gemini-Net Web 4.2 is affected by Improper Access Control in authorization logic. An...
Moderate
Unreviewed
CVE-2022-29538
was published
May 13, 2022
Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4...
High
Unreviewed
CVE-2021-26258
was published
May 13, 2022
Sysaid – Pro Plus Edition, SysAid Help Desk Broken Access Control v20.4.74 b10, v22.1.20 b62, v22...
High
Unreviewed
CVE-2022-22798
was published
May 13, 2022
ZTE's ZXMP M721 product has a permission and access control vulnerability. Since the folder...
High
Unreviewed
CVE-2022-23139
was published
May 13, 2022
Users are able to read group conversations without actively taking part in them. Next to one to...
Moderate
Unreviewed
CVE-2021-27772
was published
May 13, 2022
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE...
Moderate
Unreviewed
CVE-2022-1545
was published
May 12, 2022
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be...
Moderate
Unreviewed
CVE-2022-28774
was published
May 12, 2022
An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior...
Moderate
Unreviewed
CVE-2022-1124
was published
May 12, 2022
An improper authorization vulnerability in Palo Alto Network Cortex XSOAR software enables...
Moderate
Unreviewed
CVE-2022-0027
was published
May 12, 2022
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling...
Moderate
Unreviewed
CVE-2021-26376
was published
May 12, 2022
ProTip!
Advisories are also available from the
GraphQL API