GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
567 advisories
Filter by severity
IBM UrbanCode Deploy (UCD) 6.2.0.0 through 6.2.7.16, 7.0.0.0 through 7.0.5.11, 7.1.0.0 through 7...
Moderate
Unreviewed
CVE-2022-35716
was published
Aug 2, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could allow a user to access...
Moderate
Unreviewed
CVE-2022-22334
was published
Aug 2, 2022
The YaySMTP WordPress plugin before 2.2.1 does not have capability check before displaying the...
Moderate
Unreviewed
CVE-2022-2370
was published
Aug 2, 2022
Insufficient validation of untrusted input in File in Google Chrome on Android prior to 103.0...
Moderate
Unreviewed
CVE-2022-2479
was published
Jul 29, 2022
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53...
Moderate
Unreviewed
CVE-2022-2160
was published
Jul 29, 2022
Inappropriate implementation in PDF in Google Chrome prior to 102.0.5005.61 allowed a remote...
Moderate
Unreviewed
CVE-2022-1875
was published
Jul 28, 2022
Insufficient policy enforcement in COOP in Google Chrome prior to 102.0.5005.61 allowed a remote...
Moderate
Unreviewed
CVE-2022-1873
was published
Jul 28, 2022
Inappropriate implementation in HTML Parser in Google Chrome prior to 101.0.4951.41 allowed a...
Moderate
Unreviewed
CVE-2022-1498
was published
Jul 27, 2022
Inappropriate implementation in Extensions API in Google Chrome prior to 101.0.4951.41 allowed an...
Moderate
Unreviewed
CVE-2022-1488
was published
Jul 27, 2022
Inappropriate implementation in Web Contents in Google Chrome prior to 101.0.4951.64 allowed a...
Moderate
Unreviewed
CVE-2022-1637
was published
Jul 27, 2022
Inappropriate implementation in iframe in Google Chrome prior to 101.0.4951.41 allowed a remote...
Moderate
Unreviewed
CVE-2022-1501
was published
Jul 27, 2022
IBM Security Verify Information Queue 10.0.2 could allow a user to obtain sensitive information...
Moderate
Unreviewed
CVE-2022-35288
was published
Jul 26, 2022
Inappropriate implementation in Extensions in Google Chrome prior to 100.0.4896.60 allowed an...
Moderate
Unreviewed
CVE-2022-1137
was published
Jul 24, 2022
Inappropriate implementation in Background Fetch API in Google Chrome prior to 100.0.4896.60...
Moderate
Unreviewed
CVE-2022-1139
was published
Jul 24, 2022
Inappropriate implementation in Web Cursor in Google Chrome prior to 100.0.4896.60 allowed a...
Moderate
Unreviewed
CVE-2022-1138
was published
Jul 24, 2022
Inappropriate implementation in Resource Timing in Google Chrome prior to 100.0.4896.60 allowed a...
Moderate
Unreviewed
CVE-2022-1146
was published
Jul 24, 2022
Inappropriate implementation in Web Share API in Google Chrome on Windows prior to 100.0.4896.60...
Moderate
Unreviewed
CVE-2022-1128
was published
Jul 24, 2022
Authenticated (custom plugin role) Arbitrary File Read via Export function vulnerability in...
Moderate
Unreviewed
CVE-2022-31475
was published
Jul 22, 2022
In Montala ResourceSpace through 9.8 before r19636, csv_export_results_metadata.php allows...
Moderate
Unreviewed
CVE-2022-31260
was published
Jul 18, 2022
Pexip Infinity 27.x before 27.2 has Improper Access Control. An attacker can sometimes join a...
Moderate
Unreviewed
CVE-2022-25357
was published
Jul 18, 2022
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type...
Moderate
Unreviewed
CVE-2022-23825
was published
Jul 15, 2022
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the...
Moderate
Unreviewed
CVE-2022-2408
was published
Jul 15, 2022
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of...
Moderate
Unreviewed
CVE-2022-34765
was published
Jul 14, 2022
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions), SICAM...
Moderate
Unreviewed
CVE-2022-34464
was published
Jul 13, 2022
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to...
Moderate
Unreviewed
CVE-2022-29901
was published
Jul 13, 2022
ProTip!
Advisories are also available from the
GraphQL API