GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
915 advisories
Filter by severity
Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an...
Critical
Unreviewed
CVE-2022-33964
was published
Feb 16, 2023
Memory corruption in modem due to improper length check while copying into memory
Critical
Unreviewed
CVE-2022-25729
was published
Feb 12, 2023
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web...
Critical
Unreviewed
CVE-2022-45088
was published
Feb 12, 2023
Improper Input Validation vulnerability in Group Arge Energy and Control Systems Smartpower Web...
Critical
Unreviewed
CVE-2022-4557
was published
Feb 12, 2023
In Config Manager, there is a possible command injection due to improper input validation. This...
Critical
Unreviewed
CVE-2021-31573
was published
Feb 7, 2023
In Config Manager, there is a possible command injection due to improper input validation. This...
Critical
Unreviewed
CVE-2021-31574
was published
Feb 7, 2023
In Config Manager, there is a possible command injection due to improper input validation. This...
Critical
Unreviewed
CVE-2021-31575
was published
Feb 7, 2023
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An...
Critical
Unreviewed
CVE-2022-39060
was published
Jan 31, 2023
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input...
Critical
Unreviewed
CVE-2023-23560
was published
Jan 23, 2023
A vulnerability in the web-based management interface of Cisco Small Business RV042 Series...
Critical
Unreviewed
CVE-2023-20025
was published
Jan 20, 2023
Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow...
Critical
Unreviewed
CVE-2022-47966
was published
Jan 18, 2023
BlogEngine.NET v3.3.8.0 allows an attacker to create any folder with "files" prefix under ~...
Critical
Unreviewed
CVE-2022-41417
was published
Jan 18, 2023
Publify Improper Input Validation vulnerability
Critical
CVE-2023-0299
was published
for
publify_core
(RubyGems)
Jan 14, 2023
Apache DolphinScheduler vulnerable to Improper Input Validation
Critical
CVE-2022-45875
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Jan 4, 2023
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the...
Critical
Unreviewed
CVE-2022-34476
was published
Dec 22, 2022
Apache Karaf vulnerable to potential code injection
Critical
CVE-2022-40145
was published
for
org.apache.karaf:apache-karaf
(Maven)
Dec 21, 2022
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition...
Critical
Unreviewed
CVE-2022-4427
was published
Dec 19, 2022
An issue existed in the parsing of URLs. This issue was addressed with improved input validation....
Critical
Unreviewed
CVE-2022-42837
was published
Dec 15, 2022
GitPython vulnerable to Remote Code Execution due to improper user input validation
Critical
CVE-2022-24439
was published
for
GitPython
(pip)
Dec 6, 2022
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure...
Critical
Unreviewed
CVE-2022-43515
was published
Dec 5, 2022
iTerm2 before 3.4.18 mishandles a DECRQSS response.
Critical
Unreviewed
CVE-2022-45872
was published
Nov 24, 2022
xmldom allows multiple root nodes in a DOM
Critical
CVE-2022-39353
was published
for
@xmldom/xmldom
(npm)
Nov 1, 2022
Apache Flume vulnerable to remote code execution via deserialization of unsafe providerURL
Critical
CVE-2022-42468
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Oct 26, 2022
Insufficient validation when decoding a Socket.IO packet
Critical
CVE-2022-2421
was published
for
socket.io-parser
(npm)
Oct 26, 2022
MySQL JDBC deserialization vulnerability
Critical
CVE-2022-39312
was published
for
io.dataease:dataease-plugin-common
(Maven)
Oct 18, 2022
ProTip!
Advisories are also available from the
GraphQL API