GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,256 advisories
Filter by severity
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide...
Moderate
Unreviewed
CVE-2022-27609
was published
Apr 5, 2022
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to...
Moderate
Unreviewed
CVE-2022-27608
was published
Apr 5, 2022
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
Moderate
Unreviewed
CVE-2022-0406
was published
Apr 4, 2022
On Arista Strata family products which have “TCAM profile” feature enabled when Port IPv4 access...
High
Unreviewed
CVE-2021-28504
was published
Apr 3, 2022
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is...
High
Unreviewed
CVE-2021-32960
was published
Apr 3, 2022
Improper access control in GitLab CE/EE versions 12.4 to 14.5.4, 14.5 to 14.6.4, and 12.6 to 14.7...
Moderate
Unreviewed
CVE-2022-0373
was published
Apr 3, 2022
Improper access control in Gitlab CE/EE versions 12.7 to 14.5.4, 14.6 to 14.6.4, and 14.7 to 14.7...
Moderate
Unreviewed
CVE-2022-0390
was published
Apr 3, 2022
In RSA Archer 6.x through 6.9 SP3 (6.9.3.0), an authenticated attacker can make a GET request to...
Moderate
Unreviewed
CVE-2021-38362
was published
Apr 1, 2022
Archer 6.x through 6.9 SP2 P1 (6.9.2.1) contains an improper access control vulnerability on...
Moderate
Unreviewed
CVE-2022-26949
was published
Mar 31, 2022
Incorrect access control in NexusPHP 1.5.beta5.20120707 allows unauthorized attackers to access...
High
Unreviewed
CVE-2020-24771
was published
Mar 31, 2022
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr...
Moderate
Unreviewed
CVE-2022-1177
was published
Mar 31, 2022
In Voicemail, there is a possible way to retrieve a trackable identifier due to a missing...
Moderate
Unreviewed
CVE-2021-39742
was published
Mar 31, 2022
A flaw was found in the Linux kernels implementation of audit rules, where a syscall can...
Low
Unreviewed
CVE-2020-35501
was published
Mar 31, 2022
In PackageManager, there is a possible way to update the last usage time of another package due...
High
Unreviewed
CVE-2021-39743
was published
Mar 31, 2022
In Settings, there is a possible way to read Bluetooth device names without proper permissions...
Moderate
Unreviewed
CVE-2021-39751
was published
Mar 31, 2022
In WindowManager, there is a possible way to start non-exported and protected activities due to a...
High
Unreviewed
CVE-2021-39749
was published
Mar 31, 2022
In PackageManager, there is a possible way to change the splash screen theme of other apps due to...
High
Unreviewed
CVE-2021-39750
was published
Mar 31, 2022
In DomainVerificationService, there is a possible way to access app domain verification...
Moderate
Unreviewed
CVE-2021-39753
was published
Mar 31, 2022
In Telecom, there is a possible leak of TTY mode change due to a missing permission check. This...
High
Unreviewed
CVE-2021-39789
was published
Mar 31, 2022
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission...
High
Unreviewed
CVE-2022-20002
was published
Mar 31, 2022
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing...
High
Unreviewed
CVE-2021-39790
was published
Mar 31, 2022
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy...
High
Unreviewed
CVE-2021-3456
was published
Mar 31, 2022
The Amelia WordPress plugin before 1.0.47 does not have proper authorisation when managing...
Moderate
Unreviewed
CVE-2022-0720
was published
Mar 29, 2022
In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee...
Moderate
Unreviewed
CVE-2021-39876
was published
Mar 29, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14...
Critical
Unreviewed
CVE-2022-0735
was published
Mar 29, 2022
ProTip!
Advisories are also available from the
GraphQL API