GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,303 advisories
Filter by severity
Microsoft Office Security Feature Bypass Vulnerability.
Moderate
Unreviewed
CVE-2022-29107
was published
May 11, 2022
Windows Print Spooler Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-29114
was published
May 11, 2022
A security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE...
High
Unreviewed
CVE-2022-23705
was published
May 10, 2022
Pro Features Lock Bypass vulnerability in Countdown & Clock plugin <= 2.3.2 at WordPress.
Critical
Unreviewed
CVE-2022-29423
was published
May 7, 2022
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0...
Moderate
Unreviewed
CVE-2013-0543
was published
May 5, 2022
The OG access fields (visibility fields) implementation in Organic Groups (OG) module 7.x-2.x...
Moderate
Unreviewed
CVE-2013-4228
was published
May 5, 2022
Review Board: URL processing gives unauthorized users access to review lists
Moderate
Unreviewed
CVE-2013-4411
was published
May 5, 2022
ReviewBoard: has an access-control problem in REST API
High
Unreviewed
CVE-2013-4410
was published
May 5, 2022
Konga v0.14.9 is affected by an incorrect access control vulnerability where a specially crafted...
High
Unreviewed
CVE-2021-42192
was published
May 5, 2022
Permissions were not properly verified in the API on projects using version control in Git. This...
Moderate
Unreviewed
CVE-2022-1502
was published
May 5, 2022
An incorrect access control issue in Sandboxie Classic v5.55.13 allows attackers to cause a...
High
Unreviewed
CVE-2022-28067
was published
May 5, 2022
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may...
High
Unreviewed
CVE-2021-41020
was published
May 5, 2022
An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to...
High
Unreviewed
CVE-2022-23443
was published
May 5, 2022
In H3C MagicR100 <=V100R005, the / Ajax / ajaxget interface can be accessed without authorization...
High
Unreviewed
CVE-2022-28940
was published
May 5, 2022
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Critical
Unreviewed
CVE-2022-20777
was published
May 5, 2022
Improper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1...
Moderate
Unreviewed
CVE-2022-28782
was published
May 4, 2022
The default configuration of the Security global settings on the Citrix NetScaler Access Gateway...
Moderate
Unreviewed
CVE-2009-2213
was published
May 2, 2022
parse.c in sudo 1.6.9p17 through 1.6.9p19 does not properly interpret a system group (aka %group)...
Moderate
Unreviewed
CVE-2009-0034
was published
May 2, 2022
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive...
Moderate
Unreviewed
CVE-2008-4577
was published
May 2, 2022
Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE,...
High
Unreviewed
CVE-2008-3424
was published
May 2, 2022
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes...
Moderate
Unreviewed
CVE-2008-0595
was published
May 1, 2022
index.php in dirLIST before 0.1.1 allows remote attackers to list the contents of an excluded...
Moderate
Unreviewed
CVE-2007-3968
was published
May 1, 2022
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which...
High
Unreviewed
CVE-2007-2586
was published
May 1, 2022
Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying...
High
Unreviewed
CVE-2006-6679
was published
May 1, 2022
Raritan Dominion SX (DSX) Console Servers DSX16, DSX32, DSX4, DSX8, and DSXA-48 set (1) world...
Moderate
Unreviewed
CVE-2005-2136
was published
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API