GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,386
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,480
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
243 advisories
Filter by severity
https://www.hillstonenet.com.cn/ Hillstone Firewall SG-6000 <= 5.0.4.0 is vulnerable to Incorrect...
Critical
Unreviewed
CVE-2022-45778
was published
Dec 28, 2022
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a...
Critical
Unreviewed
CVE-2021-45466
was published
Dec 26, 2022
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform...
Critical
Unreviewed
CVE-2022-45891
was published
Dec 25, 2022
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure...
Critical
Unreviewed
CVE-2022-43515
was published
Dec 5, 2022
The web conferencing component of Mitel MiCollab through 9.6.0.13 could allow an unauthenticated...
Critical
Unreviewed
CVE-2022-41326
was published
Nov 22, 2022
Carel Boss Mini 1.5.0 has Improper Access Control.
Critical
Unreviewed
CVE-2022-34827
was published
Nov 19, 2022
Block BYPASS vulnerability in iQ Block Country plugin <= 1.2.18 on WordPress.
Critical
Unreviewed
CVE-2022-41155
was published
Nov 19, 2022
A remote unprivileged attacker can interact with the configuration interface of a Flexi-Compact...
Critical
Unreviewed
CVE-2022-27583
was published
Nov 1, 2022
A vulnerability has been identified in Siveillance Video Mobile Server V2022 R2 (All versions <...
Critical
Unreviewed
CVE-2022-43400
was published
Oct 21, 2022
Improper authorization in Dynamic Lockscreen prior to SMR Sep-2022 Release 1 in Android R(11) and...
Critical
Unreviewed
CVE-2022-39862
was published
Oct 7, 2022
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null...
Critical
Unreviewed
CVE-2022-2778
was published
Oct 1, 2022
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting...
Critical
Unreviewed
CVE-2022-39955
was published
Sep 21, 2022
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP...
Critical
Unreviewed
CVE-2022-39956
was published
Sep 21, 2022
The Linux-PAM package before 1.5.2-6.1 for openSUSE Tumbleweed allows authentication bypass for...
Critical
Unreviewed
CVE-2022-28321
was published
Sep 20, 2022
When the LDAP connector is started with StartTLS configured, unauthenticated access is granted....
Critical
Unreviewed
CVE-2022-0143
was published
Sep 20, 2022
The mobile application in Transtek Mojodat FAM (Fixed Asset Management) 2.4.6 allows remote...
Critical
Unreviewed
CVE-2022-38768
was published
Sep 14, 2022
Broken Access Control vulnerability in Alessio Caiazza's About Me plugin <= 1.0.12 at WordPress.
Critical
Unreviewed
CVE-2022-36387
was published
Sep 7, 2022
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains a vulnerability which allows...
Critical
Unreviewed
CVE-2022-37176
was published
Aug 31, 2022
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as...
Critical
Unreviewed
CVE-2022-36755
was published
Aug 29, 2022
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before...
Critical
Unreviewed
CVE-2022-25899
was published
Aug 19, 2022
The SystemUI module has a privilege escalation vulnerability. Successful exploitation of this...
Critical
Unreviewed
CVE-2022-37002
was published
Aug 11, 2022
HashiCorp Vault and Vault Enterprise through 2022-07-17 have Incorrect Access Control.
Critical
Unreviewed
CVE-2022-36129
was published
Jul 27, 2022
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88...
Critical
Unreviewed
CVE-2022-1309
was published
Jul 26, 2022
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file ...
Critical
Unreviewed
CVE-2022-26479
was published
Jul 18, 2022
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17....
Critical
Unreviewed
CVE-2022-35890
was published
Jul 16, 2022
ProTip!
Advisories are also available from the
GraphQL API