GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
198 advisories
Filter by severity
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21695
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21685
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21694
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21689
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21687
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
Multiple vulnerabilities allow bypassing path filtering of agent-to-controller access control in Jenkins
Critical
CVE-2021-21688
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
An issue in the component /cgi-bin/upload_firmware.cgi of D-Link DIR-823G REVA1 1.02B05 allows...
Critical
Unreviewed
CVE-2020-25366
was published
May 24, 2022
Pebble Templates Improper Input Validation vulnerability
Critical
CVE-2019-19899
was published
for
io.pebbletemplates:pebble-project
(Maven)
May 24, 2022
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could...
Critical
Unreviewed
CVE-2020-4926
was published
May 25, 2022
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate...
Critical
Unreviewed
CVE-2022-0885
was published
Jun 14, 2022
LRM does not implement authentication or authorization by default. A malicious actor can inject,...
Critical
Unreviewed
CVE-2022-1521
was published
Jun 25, 2022
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain...
Critical
Unreviewed
CVE-2022-35293
was published
Aug 11, 2022
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node...
Critical
Unreviewed
CVE-2022-36642
was published
Sep 3, 2022
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at...
Critical
Unreviewed
CVE-2022-37344
was published
Sep 7, 2022
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at...
Critical
Unreviewed
CVE-2022-36427
was published
Sep 7, 2022
Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code
Critical
CVE-2022-39222
was published
for
github.com/dexidp/dex
(Go)
Oct 3, 2022
Authentication Bypass by Primary Weakness in GitHub repository kareadita/kavita prior to 0.6.0.3.
Critical
Unreviewed
CVE-2022-3993
was published
Nov 14, 2022
Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
Critical
Unreviewed
CVE-2022-44584
was published
Nov 19, 2022
Missing Authorization to enable or disable users in org.xwiki.platform:xwiki-platform-user-profile-ui
Critical
CVE-2022-41930
was published
for
org.xwiki.platform:xwiki-platform-user-profile-ui
(Maven)
Nov 21, 2022
Missing Authorization in Filter Stream Converter Application of XWiki-platform
Critical
CVE-2022-41937
was published
for
org.xwiki.platform:xwiki-platform-filter-ui
(Maven)
Nov 21, 2022
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging...
Critical
Unreviewed
CVE-2022-41271
was published
Dec 13, 2022
Improper Input Validation vulnerability in Eskom Bilgisayar e-Belediye allows Information...
Critical
Unreviewed
CVE-2023-1114
was published
Mar 1, 2023
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the...
Critical
Unreviewed
CVE-2023-26957
was published
Mar 9, 2023
Access control issue in ezsystems/ezpublish-kernel
Critical
CVE-2022-48367
was published
for
ezsystems/ezpublish-kernel
(Composer)
Mar 12, 2023
The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image...
Critical
Unreviewed
CVE-2023-0349
was published
Mar 13, 2023
ProTip!
Advisories are also available from the
GraphQL API