GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Incorrect Authorization in WildFly Elytron
High
CVE-2020-1748
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Feb 15, 2022
Reject unauthorized access with GitHub PATs
High
CVE-2021-21432
was published
for
github.com/go-vela/server
(Go)
Feb 15, 2022
Duplicate Advisory: Incorrect Access Control in github.com/nats-io/jwt and github.com/nats-io/nats-server/v2
High
GHSA-9r5x-fjv3-q6h4
was published
for
github.com/nats-io/jwt
(Go)
Feb 15, 2022
•
withdrawn
Affected versions of Atlassian Jira Service Management Server and Data Center allow authenticated...
Moderate
Unreviewed
CVE-2021-43948
was published
Feb 16, 2022
Improper Access Control in librenms
High
CVE-2022-0580
was published
for
librenms/librenms
(Composer)
Feb 16, 2022
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests...
High
Unreviewed
CVE-2021-3560
was published
Feb 17, 2022
VMware ESXi contains an unauthorized access vulnerability due to VMX having access to settingsd...
High
Unreviewed
CVE-2021-22042
was published
Feb 17, 2022
The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly...
Moderate
Unreviewed
CVE-2022-0633
was published
Feb 18, 2022
Incorrect authorization in Drupal core
Moderate
CVE-2022-25270
was published
for
drupal/core
(Composer)
Feb 18, 2022
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C...
Critical
Unreviewed
CVE-2022-21141
was published
Feb 19, 2022
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C...
Critical
Unreviewed
CVE-2022-21196
was published
Feb 19, 2022
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of...
High
Unreviewed
CVE-2020-25722
was published
Feb 19, 2022
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an...
Moderate
Unreviewed
CVE-2022-25318
was published
Feb 19, 2022
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have authorisation...
Moderate
Unreviewed
CVE-2022-0164
was published
Feb 22, 2022
Incorrect Authorization in runc
High
CVE-2019-16884
was published
for
github.com/opencontainers/runc
(Go)
Feb 22, 2022
Improper Authorization in dolibarr/dolibarr
Moderate
CVE-2022-0731
was published
for
dolibarr/dolibarr
(Composer)
Feb 24, 2022
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
Moderate
Unreviewed
CVE-2022-0727
was published
Feb 24, 2022
Improper Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
Moderate
Unreviewed
CVE-2022-0726
was published
Feb 24, 2022
The backend infrastructure shared by multiple mobile device monitoring services does not...
High
Unreviewed
CVE-2022-0732
was published
Feb 25, 2022
An incorrect access control issue in HMS v1.0 allows unauthenticated attackers to read and modify...
Critical
Unreviewed
CVE-2022-25402
was published
Feb 25, 2022
Access Control vulnerability within CoreNLP
Critical
CVE-2021-44550
was published
for
edu.stanford.nlp:stanford-corenlp
(Maven)
Feb 25, 2022
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon...
High
Unreviewed
CVE-2019-25058
was published
Feb 25, 2022
Exposure of Resource to Wrong Sphere in microweber
Moderate
CVE-2022-0762
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Incorrect Authorization and Exposure of Sensitive Information to an Unauthorized Actor in scrapy
Moderate
CVE-2022-0577
was published
for
scrapy
(pip)
Mar 1, 2022
ProTip!
Advisories are also available from the
GraphQL API