GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,112
Maven
5,000+
npm
3,767
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
991 advisories
Filter by severity
MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability...
High
Unreviewed
CVE-2021-39972
was published
Jan 4, 2022
Improper access control while doing XPU re-configuration dynamically can lead to unauthorized...
High
Unreviewed
CVE-2021-30276
was published
Jan 4, 2022
Policy bypass in COOP in Google Chrome prior to 98.0.4758.80 allowed a remote attacker to bypass...
Moderate
Unreviewed
CVE-2022-0461
was published
Apr 6, 2022
A remote, unauthenticated attacker could utilize the control programmer of the CODESYS Control...
High
Unreviewed
CVE-2022-22515
was published
Apr 8, 2022
IBM SterlingPartner Engagement Manager 6.2.0 could allow a remote authenticated attacker to...
High
Unreviewed
CVE-2022-22331
was published
Apr 2, 2022
Data leak in Canvas in Google Chrome prior to 99.0.4844.51 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2022-0806
was published
Apr 6, 2022
A business logic error in Project Import in GitLab CE/EE versions 14.9 prior to 14.9.2, 14.8...
Low
Unreviewed
CVE-2022-1111
was published
Apr 5, 2022
In code generated by BuildParcelFields of generate_cpp.cpp, there is a possible way for a crafted...
Moderate
Unreviewed
CVE-2021-0966
was published
Dec 16, 2021
In requestRouteToHostAddress of ConnectivityService.java, there is a possible way to determine...
Low
Unreviewed
CVE-2021-0994
was published
Dec 16, 2021
In Telephony, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39777
was published
Mar 31, 2022
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter...
Moderate
Unreviewed
CVE-2021-29867
was published
Dec 4, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application...
Moderate
Unreviewed
CVE-2021-29716
was published
Dec 4, 2021
In PermissionController, there is a possible permission bypass due to an unsafe PendingIntent....
Moderate
Unreviewed
CVE-2021-39757
was published
Mar 31, 2022
In getOrganizationNameForUser of DevicePolicyManagerService.java, there is a possible...
Low
Unreviewed
CVE-2021-0982
was published
Dec 16, 2021
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory...
Moderate
Unreviewed
CVE-2021-39648
was published
Dec 16, 2021
On unix-like systems, the system temporary directory is shared between all users on that system....
Moderate
Unreviewed
CVE-2021-22572
was published
Mar 30, 2022
GE UR firmware versions prior to version 8.1x shares MODBUS memory map as part of the...
Moderate
Unreviewed
CVE-2021-27424
was published
Mar 24, 2022
OpenEMR v6.0.0 was discovered to contain an incorrect access control issue.
Moderate
Unreviewed
CVE-2022-25041
was published
Mar 25, 2022
Gradle Enterprise before 2022.1 allows remote code execution if the installation process did not...
Critical
Unreviewed
CVE-2022-27919
was published
Mar 26, 2022
A permissions issue was addressed with improved validation. This issue is fixed in Security...
Moderate
Unreviewed
CVE-2022-22583
was published
Mar 19, 2022
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin...
High
Unreviewed
CVE-2022-26267
was published
Mar 20, 2022
The GSMA authentication panel could be presented on the lock screen. The issue was resolved by...
Moderate
Unreviewed
CVE-2022-22652
was published
Mar 19, 2022
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control.
High
Unreviewed
CVE-2022-23345
was published
Mar 22, 2022
An issue with app access to camera metadata was addressed with improved logic. This issue is...
Low
Unreviewed
CVE-2022-22598
was published
Mar 19, 2022
An information disclosure issue was addressed with improved state management. This issue is fixed...
High
Unreviewed
CVE-2022-22579
was published
Mar 19, 2022
ProTip!
Advisories are also available from the
GraphQL API