GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
150 advisories
Filter by severity
Vulnerability of HwWatchHealth being hijacked.Successful exploitation of this vulnerability may...
Moderate
Unreviewed
CVE-2023-34157
was published
Jun 16, 2023
An issue has been discovered in GitLab CE/EE affecting all versions before 15.10.8, all versions...
Moderate
Unreviewed
CVE-2023-2001
was published
Jun 7, 2023
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to...
Moderate
Unreviewed
CVE-2023-0816
was published
Mar 27, 2023
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Moderate
Unreviewed
CVE-2023-21794
was published
Feb 14, 2023
When exiting fullscreen mode, an iframe could have confused the browser about the current state...
Moderate
Unreviewed
CVE-2022-31738
was published
Dec 22, 2022
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and...
Moderate
Unreviewed
CVE-2022-41798
was published
Dec 5, 2022
WithSecure through 2022-08-10 allows attackers to cause a denial of service (issue 3 of 5).
Moderate
Unreviewed
CVE-2022-38164
was published
Nov 8, 2022
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the...
Moderate
Unreviewed
CVE-2022-38712
was published
Nov 4, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations...
Moderate
Unreviewed
CVE-2021-27854
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed...
Moderate
Unreviewed
CVE-2021-27853
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27862
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to...
Moderate
Unreviewed
CVE-2022-37709
was published
Sep 17, 2022
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking...
Moderate
Unreviewed
CVE-2022-33991
was published
Aug 16, 2022
Due to a bug in the handling of the communication between the client and server, it was possible...
Moderate
Unreviewed
CVE-2022-35629
was published
Jul 30, 2022
Incorrect security UI in Downloads in Google Chrome on Android prior to 101.0.4951.41 allowed a...
Moderate
Unreviewed
CVE-2022-1495
was published
Jul 27, 2022
Inappropriate implementation in compositing in Google Chrome prior to 100.0.4896.88 allowed a...
Moderate
Unreviewed
CVE-2022-1306
was published
Jul 26, 2022
Inappropriate implementation in full screen in Google Chrome on Android prior to 100.0.4896.88...
Moderate
Unreviewed
CVE-2022-1307
was published
Jul 26, 2022
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 100.0.4896...
Moderate
Unreviewed
CVE-2022-1129
was published
Jul 24, 2022
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password
Moderate
CVE-2022-2368
was published
for
microweber/microweber
(Composer)
Jul 12, 2022
Knot Resolver through 5.5.1 may allow DNS cache poisoning when there is an attempt to limit...
Moderate
Unreviewed
CVE-2022-32983
was published
Jun 21, 2022
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2....
Moderate
Unreviewed
CVE-2021-32076
was published
May 24, 2022
Legacy pairing and secure-connections pairing authentication in Bluetooth® BR/EDR Core...
Moderate
Unreviewed
CVE-2020-10135
was published
May 24, 2022
Yandex Browser before 20.10.0 allows remote attackers to spoof the address bar
Moderate
Unreviewed
CVE-2020-27970
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API