GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
327 advisories
Filter by severity
An issue in the component global.so of Totolink A830R V4.1.2cu.5182 allows attackers to bypass...
Critical
Unreviewed
CVE-2022-48066
was published
Jan 27, 2023
JWT audience claim is not verified
Critical
CVE-2023-22482
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 25, 2023
An incorrect authorization vulnerability was identified in GitHub Enterprise Server, allowing for...
Critical
Unreviewed
CVE-2022-23739
was published
Jan 17, 2023
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect...
Critical
Unreviewed
CVE-2022-45778
was published
Dec 28, 2022
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a...
Critical
Unreviewed
CVE-2021-45466
was published
Dec 26, 2022
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform...
Critical
Unreviewed
CVE-2022-45891
was published
Dec 25, 2022
Multiple vulnerabilities in extension "Newsletter subscriber management" (fp_newsletter)
Critical
CVE-2022-47408
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure...
Critical
Unreviewed
CVE-2022-43515
was published
Dec 5, 2022
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated...
Critical
Unreviewed
CVE-2022-41326
was published
Nov 22, 2022
Carel Boss Mini 1.5.0 has Improper Access Control.
Critical
Unreviewed
CVE-2022-34827
was published
Nov 19, 2022
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
Critical
Unreviewed
CVE-2022-41155
was published
Nov 19, 2022
Spring Security authorization rules can be bypassed via forward or include dispatcher types
Critical
CVE-2022-31692
was published
for
org.springframework.security:spring-security-core
(Maven)
Nov 1, 2022
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact...
Critical
Unreviewed
CVE-2022-27583
was published
Nov 1, 2022
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions <...
Critical
Unreviewed
CVE-2022-43400
was published
Oct 21, 2022
Field-level access-control bypass for multiselect field
Critical
CVE-2022-39322
was published
for
@keystone-6/core
(npm)
Oct 18, 2022
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and...
Critical
Unreviewed
CVE-2022-39862
was published
Oct 7, 2022
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null...
Critical
Unreviewed
CVE-2022-2778
was published
Oct 1, 2022
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP...
Critical
Unreviewed
CVE-2022-39956
was published
Sep 21, 2022
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting...
Critical
Unreviewed
CVE-2022-39955
was published
Sep 21, 2022
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted....
Critical
Unreviewed
CVE-2022-0143
was published
Sep 20, 2022
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for...
Critical
Unreviewed
CVE-2022-28321
was published
Sep 20, 2022
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote...
Critical
Unreviewed
CVE-2022-38768
was published
Sep 14, 2022
Pebble Templates protection mechanism bypass can lead to arbitrary code execution
Critical
CVE-2022-37767
was published
for
io.pebbletemplates:pebble
(Maven)
Sep 13, 2022
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
Critical
Unreviewed
CVE-2022-36387
was published
Sep 7, 2022
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows...
Critical
Unreviewed
CVE-2022-37176
was published
Aug 31, 2022
ProTip!
Advisories are also available from the
GraphQL API