GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,605
Maven
5,000+
npm
4,250
NuGet
757
pip
4,016
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,924 advisories
Filter by severity
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker...
High
Unreviewed
CVE-2021-20049
was published
Dec 24, 2021
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download...
High
Unreviewed
CVE-2022-26591
was published
Apr 7, 2022
IBM Aspera High-Speed Transfer 4.3.1 and earlier could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2022-22391
was published
Apr 15, 2022
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
High
Unreviewed
CVE-2022-27849
was published
Apr 16, 2022
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which...
High
Unreviewed
CVE-2021-43287
was published
Apr 15, 2022
An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in...
Moderate
Unreviewed
CVE-2022-25166
was published
Apr 15, 2022
The kernel in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly restrict the...
Moderate
Unreviewed
CVE-2015-3766
was published
May 17, 2022
Lockbox in EMC Documentum D2 before 4.5 uses a hardcoded passphrase when a server lacks a D2...
Low
Unreviewed
CVE-2015-4537
was published
May 17, 2022
Sensitive Information Exposure in E4J s.r.l. VikBooking Hotel Booking Engine & PMS plugin <= 1.5...
Moderate
Unreviewed
CVE-2022-27863
was published
Apr 20, 2022
Under certain conditions, SAP BusinessObjects Business Intelligence platform, Client Management...
High
Unreviewed
CVE-2022-27667
was published
Apr 13, 2022
ImageIO in Apple iOS before 8.4.1 and OS X before 10.10.5 does not properly initialize an...
Moderate
Unreviewed
CVE-2015-5782
was published
May 17, 2022
CloudKit in Apple iOS before 8.4.1 and OS X before 10.10.5 allows attackers to access an iCloud...
Moderate
Unreviewed
CVE-2015-3782
was published
May 17, 2022
Argo CD will blindly trust JWT claims if anonymous access is enabled
Critical
CVE-2022-29165
was published
for
github.com/argoproj/argo-cd
(Go)
May 24, 2022
Office Viewer in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to read...
Moderate
Unreviewed
CVE-2015-3784
was published
May 17, 2022
A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions), Mendix...
High
Unreviewed
CVE-2022-27241
was published
Apr 13, 2022
Joomla! Core is prone to an information disclosure vulnerability. Attackers can exploit this...
High
Unreviewed
CVE-2010-1432
was published
Apr 21, 2022
A vulnerability in the XSI-Actions interface of Cisco BroadWorks Application Server could allow...
Moderate
Unreviewed
CVE-2021-1562
was published
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in DisCatSharp
Moderate
CVE-2022-24849
was published
for
DisCatSharp
(NuGet)
Apr 22, 2022
bootp in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to obtain...
Low
Unreviewed
CVE-2015-3778
was published
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in nanoid
Moderate
CVE-2021-23566
was published
for
nanoid
(npm)
Jan 21, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Low
CVE-2017-3589
was published
for
mysql:mysql-connector-java
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Elasticsearch
Moderate
CVE-2018-17244
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Moderate
CVE-2018-1000169
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
High
CVE-2017-12616
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Moderate
CVE-2016-5001
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API