GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
287 advisories
Filter by severity
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to...
High
Unreviewed
CVE-2022-4550
was published
Feb 27, 2023
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Moderate
Unreviewed
CVE-2023-21794
was published
Feb 14, 2023
Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series...
High
Unreviewed
CVE-2022-40269
was published
Feb 2, 2023
Parse Server option `masterKeyIps` vulnerability to IP spoofing
High
CVE-2023-22474
was published
for
parse-server
(npm)
Jan 31, 2023
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP...
High
Unreviewed
CVE-2022-4303
was published
Jan 23, 2023
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from...
High
Unreviewed
CVE-2022-4746
was published
Jan 23, 2023
When exiting fullscreen mode, an iframe could have confused the browser about the current state...
Moderate
Unreviewed
CVE-2022-31738
was published
Dec 22, 2022
Microsoft Outlook for Mac Spoofing Vulnerability.
High
Unreviewed
CVE-2022-44713
was published
Dec 13, 2022
Multiple Wiesemann&Theis products of the ComServer Series are prone to an authentication bypass...
High
Unreviewed
CVE-2022-4098
was published
Dec 13, 2022
Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and...
Moderate
Unreviewed
CVE-2022-41798
was published
Dec 5, 2022
Velneo vClient on its 28.1.3 version, could allow an attacker with knowledge of the victims's...
High
Unreviewed
CVE-2021-45036
was published
Nov 28, 2022
WithSecure through 2022-08-10 allows attackers to cause a denial of service (issue 3 of 5).
Moderate
Unreviewed
CVE-2022-38164
was published
Nov 8, 2022
"IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 Web services could allow a man-in-the...
Moderate
Unreviewed
CVE-2022-38712
was published
Nov 4, 2022
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing...
High
Unreviewed
CVE-2022-42983
was published
Oct 17, 2022
An authentication bypass vulnerability in the Palo Alto Networks PAN-OS 8.1 web interface allows...
High
Unreviewed
CVE-2022-0030
was published
Oct 12, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using combinations...
Moderate
Unreviewed
CVE-2021-27854
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed...
Moderate
Unreviewed
CVE-2021-27853
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27862
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
python-jwt vulnerable to token forgery with new claims
Critical
CVE-2022-39227
was published
for
python-jwt
(pip)
Sep 21, 2022
Tesla Model 3 V11.0(2022.4.5.1 6b701552d7a6) Tesla mobile app v4.23 is vulnerable to...
Moderate
Unreviewed
CVE-2022-37709
was published
Sep 17, 2022
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it....
High
Unreviewed
CVE-2022-32744
was published
Aug 26, 2022
dproxy-nexgen (aka dproxy nexgen) forwards and caches DNS queries with the CD (aka checking...
Moderate
Unreviewed
CVE-2022-33991
was published
Aug 16, 2022
ProTip!
Advisories are also available from the
GraphQL API