GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,350
Erlang
31
GitHub Actions
22
Go
2,119
Maven
5,000+
npm
3,778
NuGet
680
pip
3,459
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
906 advisories
Filter by severity
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission...
High
Unreviewed
CVE-2022-20002
was published
Mar 31, 2022
In Dialer, there is a possible way to manipulate visual voicemail settings due to a missing...
High
Unreviewed
CVE-2021-39790
was published
Mar 31, 2022
An improper authorization handling flaw was found in Foreman. The Salt plugin for the smart-proxy...
High
Unreviewed
CVE-2021-3456
was published
Mar 31, 2022
Incorrect Authorization in imgcrypt
High
CVE-2022-24778
was published
for
github.com/containerd/imgcrypt
(Go)
Mar 28, 2022
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all...
High
Unreviewed
CVE-2021-27474
was published
Mar 24, 2022
A flaw was found in Quarkus. The state and potentially associated permissions can leak from one...
High
Unreviewed
CVE-2022-0981
was published
Mar 24, 2022
The Advanced Contact form 7 DB WordPress plugin before 1.8.7 does not have authorisation nor CSRF...
High
Unreviewed
CVE-2021-24905
was published
Mar 22, 2022
This issue was addressed with improved checks. This issue is fixed in watchOS 8.5, iOS 15.4 and...
High
Unreviewed
CVE-2022-22618
was published
Mar 19, 2022
Information Exposure in Apache Tapestry
High
CVE-2021-30638
was published
for
org.apache.tapestry:tapestry-core
(Maven)
Mar 18, 2022
In Gradle Enterprise before 2021.4.2, the default built-in build cache configuration allowed...
High
Unreviewed
CVE-2022-25364
was published
Mar 18, 2022
Improper Authorization in org.cometd.oort
High
CVE-2022-24721
was published
for
org.cometd.java:cometd-java-oort
(Maven)
Mar 15, 2022
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension...
High
Unreviewed
CVE-2022-24128
was published
Mar 14, 2022
An issue was discovered in Luna Simo PPR1.180610.011/202001031830. A pre-installed app with a...
High
Unreviewed
CVE-2021-41850
was published
Mar 13, 2022
Duplicate Advisory: Improper Authorization in Gogs
High
GHSA-65f3-3278-7m65
was published
for
gogs.io/gogs
(Go)
Mar 12, 2022
•
withdrawn
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) uses the "...
High
Unreviewed
CVE-2021-42855
was published
Mar 11, 2022
Improper access control vulnerability in dynamic receiver in ApkInstaller prior to SMR MAR-2022...
High
Unreviewed
CVE-2022-24931
was published
Mar 11, 2022
Improper access control on the LocalClientList.asp interface allows an unauthenticated remote...
High
Unreviewed
CVE-2022-25214
was published
Mar 11, 2022
Incorrect Authorization in @uppy/companion
High
CVE-2022-0528
was published
for
@uppy/companion
(npm)
Mar 4, 2022
Improper Access Control to Remote Code Execution in GitHub repository webmin/webmin prior to 1.990.
High
Unreviewed
CVE-2022-0824
was published
Mar 3, 2022
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
High
Unreviewed
CVE-2022-0829
was published
Mar 3, 2022
A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5...
High
Unreviewed
CVE-2022-22300
was published
Mar 2, 2022
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon...
High
Unreviewed
CVE-2019-25058
was published
Feb 25, 2022
The backend infrastructure shared by multiple mobile device monitoring services does not...
High
Unreviewed
CVE-2022-0732
was published
Feb 25, 2022
Incorrect Authorization in runc
High
CVE-2019-16884
was published
for
github.com/opencontainers/runc
(Go)
Feb 22, 2022
Multiple flaws were found in the way samba AD DC implemented access and conformance checking of...
High
Unreviewed
CVE-2020-25722
was published
Feb 19, 2022
ProTip!
Advisories are also available from the
GraphQL API