GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
987 advisories
Filter by severity
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions...
Moderate
Unreviewed
CVE-2022-39877
was published
Oct 7, 2022
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive...
Moderate
Unreviewed
CVE-2022-36772
was published
Oct 7, 2022
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4...
Moderate
Unreviewed
CVE-2022-32781
was published
Sep 25, 2022
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4...
Moderate
Unreviewed
CVE-2022-32782
was published
Sep 25, 2022
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
Moderate
CVE-2022-38512
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 23, 2022
matrix-appservice-irc vulnerable to IRC mode parameter confusion
Moderate
CVE-2022-39202
was published
for
matrix-appservice-irc
(npm)
Sep 15, 2022
The HoYoVerse (formerly miHoYo) Genshin Impact mhyprot2.sys 1.0.0.0 anti-cheat driver does not...
Moderate
Unreviewed
CVE-2020-36603
was published
Sep 15, 2022
IBM Db2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, 11.1, and 11.5 is vulnerable to an...
Moderate
Unreviewed
CVE-2022-22483
was published
Sep 14, 2022
Authenticated (subscriber+) Plugin Setting change vulnerability in WP Shamsi plugin <= 4.1.1 at...
Moderate
Unreviewed
CVE-2022-38058
was published
Sep 10, 2022
Custom permission misuse vulnerability in SystemUI prior to SMR Sep-2022 Release 1 allows...
Moderate
Unreviewed
CVE-2022-36861
was published
Sep 10, 2022
An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6...
Moderate
Unreviewed
CVE-2021-43076
was published
Sep 7, 2022
A privilege escalation flaw was found in the Ansible Automation Platform. This flaw allows a...
Moderate
Unreviewed
CVE-2022-2568
was published
Aug 19, 2022
In Settings, there is a possible way to bypass factory reset permissions due to a permissions...
Moderate
Unreviewed
CVE-2022-20265
was published
Aug 13, 2022
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-35774
was published
Aug 10, 2022
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-35780
was published
Aug 10, 2022
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-35782
was published
Aug 10, 2022
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-35775
was published
Aug 10, 2022
Azure Site Recovery Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022...
Moderate
Unreviewed
CVE-2022-35781
was published
Aug 10, 2022
In BIG-IP Versions 17.0.x before 17.0.0.1, 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x...
Moderate
Unreviewed
CVE-2022-33962
was published
Aug 5, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, and 21.0.2 could disclose sensitive information...
Moderate
Unreviewed
CVE-2022-34338
was published
Aug 2, 2022
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2022-20906
was published
Jul 23, 2022
Multiple vulnerabilities in Cisco Nexus Dashboard could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2022-20907
was published
Jul 23, 2022
Broken Access Control vulnerability in YIKES Inc. Custom Product Tabs for WooCommerce plugin <= 1...
Moderate
Unreviewed
CVE-2022-28666
was published
Jul 22, 2022
A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4...
Moderate
Unreviewed
CVE-2022-26118
was published
Jul 19, 2022
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated...
Moderate
Unreviewed
CVE-2022-34754
was published
Jul 14, 2022
ProTip!
Advisories are also available from the
GraphQL API