GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,154
Erlang
30
GitHub Actions
19
Go
1,966
Maven
5,000+
npm
3,694
NuGet
652
pip
3,311
Pub
11
RubyGems
881
Rust
831
Swift
35
Unreviewed advisories
All unreviewed
5,000+
44 advisories
Filter by severity
Incorrect Resource Transfer Between Spheres in Grails
High
CVE-2019-12728
was published
for
org.grails:grails-core
(Maven)
May 24, 2022
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could allow...
High
Unreviewed
CVE-2022-30236
was published
Jun 3, 2022
The web server in Aternity before 9.0.1 does not require authentication for getMBeansFromURL...
Critical
Unreviewed
CVE-2016-5062
was published
May 17, 2022
parse-server's session object properties can be updated by foreign user if object ID is known
Moderate
CVE-2022-39225
was published
for
parse-server
(npm)
Sep 21, 2022
Incorrect Resource Transfer Between Spheres in eclipse-wtp
Moderate
CVE-2019-10753
was published
for
com.diffplug.spotless:spotless-eclipse-cdt
(Maven)
Sep 11, 2019
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4...
High
Unreviewed
CVE-2021-22900
was published
May 24, 2022
Unisphere for PowerMax versions before 9.2.3.15 contain a privilege escalation vulnerability. An...
High
Unreviewed
CVE-2022-31233
was published
Sep 1, 2022
V6.0.10P2T2 and V6.0.10P2T5 of F6x2W product are impacted by Information leak vulnerability....
Moderate
Unreviewed
CVE-2020-6862
was published
May 24, 2022
An elevation of privilege vulnerability exists when the Windows Print Spooler service improperly...
High
Unreviewed
CVE-2020-1048
was published
May 24, 2022
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a client-side control...
Moderate
Unreviewed
CVE-2020-27268
was published
May 24, 2022
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user...
Critical
Unreviewed
CVE-2020-24683
was published
May 24, 2022
Dell Unisphere for PowerMax versions prior to 9.2.1.6 contain an Authorization Bypass...
High
Unreviewed
CVE-2021-21531
was published
May 24, 2022
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another...
High
Unreviewed
CVE-2021-20411
was published
May 24, 2022
Firefox used to cache the last filename used for printing a file. When generating a filename for...
Moderate
Unreviewed
CVE-2021-29960
was published
May 24, 2022
Dell EMC iDRAC9 versions prior to 4.40.00.00 contain an improper authentication vulnerability. A...
Moderate
Unreviewed
CVE-2021-21544
was published
May 24, 2022
The HM Multiple Roles WordPress plugin before 1.3 does not have any access control to prevent low...
High
Unreviewed
CVE-2021-24602
was published
May 24, 2022
Opera does not prevent cookies that are sent over an insecure channel (HTTP) from also being sent...
Moderate
Unreviewed
CVE-2004-0872
was published
Apr 29, 2022
SMTP service in Microsoft Windows 2000, Windows XP Professional, and Exchange 2000 allows remote...
Moderate
Unreviewed
CVE-2002-0055
was published
Apr 30, 2022
Elrond-GO processing: fallback search of SCRs when not found in the main cache
High
CVE-2022-46173
was published
for
github.com/ElrondNetwork/elrond-go
(Go)
Dec 30, 2022
A Client-Side Enforcement of Server-Side Security issue was discovered in ProMinent MultiFLEX...
Moderate
Unreviewed
CVE-2017-14013
was published
May 13, 2022
In MB connect line mymbCONNECT24, mbCONNECT24 in versions <= 2.8.0 an authenticated attacker can...
Moderate
Unreviewed
CVE-2021-34574
was published
May 24, 2022
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability....
High
Unreviewed
CVE-2021-36338
was published
Jan 22, 2022
OpenZeppelin Contracts's Cross chain utilities for Arbitrum L2 see EOA calls as cross chain calls
Moderate
CVE-2022-35916
was published
for
@openzeppelin/contracts
(npm)
Aug 14, 2022
Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS
High
CVE-2019-10248
was published
for
org.eclipse.vorto:org.eclipse.vorto.core
(Maven)
May 24, 2022
A vulnerability in the web-based management interface of Cisco Unified Contact Center Management...
Critical
Unreviewed
CVE-2022-20658
was published
Jan 15, 2022
ProTip!
Advisories are also available from the
GraphQL API