GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,342
Erlang
31
GitHub Actions
22
Go
2,106
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
986 advisories
Filter by severity
A vulnerability is in the 'live_mfg.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6...
High
Unreviewed
CVE-2021-44260
was published
Mar 18, 2022
A vulnerability is in the 'MNU_top.htm' page of the Netgear W104, version WAC104-V1.0.4.13, which...
High
Unreviewed
CVE-2021-44262
was published
Mar 18, 2022
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6...
Critical
Unreviewed
CVE-2021-44259
was published
Mar 18, 2022
A vulnerability is in the 'BRS_top.html' page of the Netgear W104, version WAC104-V1.0.4.13,...
Moderate
Unreviewed
CVE-2021-44261
was published
Mar 18, 2022
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Critical
Unreviewed
CVE-2022-26501
was published
Mar 18, 2022
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows...
Critical
Unreviewed
CVE-2022-25251
was published
Mar 17, 2022
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an...
Critical
Unreviewed
CVE-2022-25247
was published
Mar 17, 2022
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows...
High
Unreviewed
CVE-2022-25250
was published
Mar 17, 2022
Improper Authentication in FreeTAKServer
High
CVE-2022-25508
was published
for
FreeTAKServer
(pip)
Mar 12, 2022
atune before 0.3-0.8 log in as a local user and run the curl command to access the local atune...
High
Unreviewed
CVE-2021-33658
was published
Mar 12, 2022
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any...
High
Unreviewed
CVE-2022-24396
was published
Mar 11, 2022
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic...
Critical
Unreviewed
CVE-2022-25922
was published
Mar 11, 2022
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business...
Critical
Unreviewed
CVE-2022-26143
was published
Mar 11, 2022
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands...
Critical
Unreviewed
CVE-2020-10640
was published
Feb 25, 2022
Denial of service in Grafana
Moderate
CVE-2021-27358
was published
for
github.com/grafana/grafana
(Go)
Feb 15, 2022
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily...
Moderate
Unreviewed
CVE-2022-0188
was published
Feb 15, 2022
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause...
Critical
Unreviewed
CVE-2021-22805
was published
Feb 12, 2022
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause...
Critical
Unreviewed
CVE-2021-22823
was published
Feb 12, 2022
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow...
Moderate
Unreviewed
CVE-2022-22809
was published
Feb 11, 2022
In Mahara 21.04 before 21.04.3 and 21.10 before 21.10.1, portfolios created in groups that have...
Moderate
Unreviewed
CVE-2022-24111
was published
Feb 11, 2022
Missing Authentication for Critical Function in Apache TomEE
High
CVE-2020-11969
was published
for
org.apache.tomee:tomee
(Maven)
Feb 10, 2022
Improper Authentication in Apache Spark
Critical
CVE-2020-9480
was published
for
org.apache.spark:spark-parent_2.11
(Maven)
Feb 10, 2022
Authentication bypass in Apache Hadoop
High
CVE-2018-11764
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Feb 10, 2022
A denial of service vulnerability exists in the Modbus configuration functionality of Sealevel...
High
Unreviewed
CVE-2021-21964
was published
Feb 10, 2022
Remote code execution in Apache TomEE
Critical
CVE-2020-13931
was published
for
org.apache.tomee:apache-tomee
(Maven)
Feb 9, 2022
ProTip!
Advisories are also available from the
GraphQL API