GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,337 advisories
Filter by severity
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed...
Moderate
Unreviewed
CVE-2022-2861
was published
Sep 27, 2022
Missing permission check in Jenkins build-publisher Plugin
Moderate
CVE-2022-41230
was published
for
org.jenkins-ci.plugins:build-publisher
(Maven)
Sep 22, 2022
This issue was addressed with improved checks. This issue is fixed in iOS 15.7 and iPadOS 15.7,...
Moderate
Unreviewed
CVE-2022-32854
was published
Sep 21, 2022
Docker supplementary group permissions not set up properly, allowing attackers to bypass primary group restrictions
Moderate
CVE-2022-36109
was published
for
github.com/docker/docker
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when updating a robot account
Moderate
CVE-2022-31667
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Harbor fails to validate the user permissions when updating tag immutability policies
Moderate
CVE-2022-31669
was published
for
github.com/goharbor/harbor
(Go)
Sep 16, 2022
Improper Authorization vulnerability in setDualDARPolicyCmd prior to SMR Sep-2022 Release 1...
Moderate
Unreviewed
CVE-2022-36848
was published
Sep 10, 2022
Harbor fails to validate the user permissions when reading job execution logs through the P2P preheat execution logs
Moderate
CVE-2022-31671
was published
for
github.com/goharbor/harbor
(Go)
Sep 9, 2022
Blackboard Learn 1.10.1 allows remote authenticated users to read unintended files by entering...
Moderate
Unreviewed
CVE-2022-39196
was published
Sep 6, 2022
openstack-barbican Denial of Service vulnerability
Moderate
CVE-2022-23452
was published
for
barbican
(pip)
Sep 2, 2022
OpenShift doesn't properly verify subdomain ownership, which allows route takeover. Once a custom...
Moderate
Unreviewed
CVE-2022-2220
was published
Sep 1, 2022
gomatrixserverlib and Dendrite vulnerable to incorrect parsing of the event default power level in event auth
Moderate
CVE-2022-36009
was published
for
github.com/matrix-org/dendrite
(Go)
Aug 30, 2022
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment...
Moderate
Unreviewed
CVE-2022-36121
was published
Aug 27, 2022
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment...
Moderate
Unreviewed
CVE-2022-36116
was published
Aug 26, 2022
An issue was discovered in Blue Prism Enterprise 6.0 through 7.01. In a misconfigured environment...
Moderate
Unreviewed
CVE-2022-36118
was published
Aug 26, 2022
A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing...
Moderate
Unreviewed
CVE-2021-3763
was published
Aug 24, 2022
Magento Open Source has Improper Access Control vulnerability
Moderate
CVE-2022-35692
was published
for
magento/community-edition
(Composer)
Aug 20, 2022
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may...
Moderate
Unreviewed
CVE-2022-21140
was published
Aug 19, 2022
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check...
Moderate
Unreviewed
CVE-2022-20326
was published
Aug 13, 2022
In PackageManager, there is a possible package installation disclosure due to a missing...
Moderate
Unreviewed
CVE-2022-20323
was published
Aug 13, 2022
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access...
Moderate
Unreviewed
CVE-2022-28754
was published
Aug 12, 2022
Zoom On-Premise Meeting Connector MMR before version 4.8.129.20220714 contains an improper access...
Moderate
Unreviewed
CVE-2022-28753
was published
Aug 12, 2022
In Zammad 5.2.0, customers who have secondary organizations assigned were able to see all...
Moderate
Unreviewed
CVE-2022-35489
was published
Aug 9, 2022
XMLUI's metadata of withdrawn Items is exposed to anonymous users
Moderate
CVE-2022-31190
was published
for
org.dspace:dspace-xmlui
(Maven)
Aug 6, 2022
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before...
Moderate
Unreviewed
CVE-2022-2095
was published
Aug 6, 2022
ProTip!
Advisories are also available from the
GraphQL API