GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
288,473 advisories
Filter by severity
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm...
High
Unreviewed
CVE-2022-31325
was published
Jun 9, 2022
The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields,...
Moderate
Unreviewed
CVE-2022-1506
was published
Jun 9, 2022
The Logo Slider WordPress plugin through 1.4.8 does not sanitise and escape the lsp_slider_id...
Moderate
Unreviewed
CVE-2022-1687
was published
Jun 9, 2022
ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management...
High
Unreviewed
CVE-2021-36710
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD...
Critical
Unreviewed
CVE-2022-30909
was published
Jun 9, 2022
A vulnerability, which was classified as critical, has been found in The Next Generation of...
High
Unreviewed
CVE-2017-20017
was published
Jun 9, 2022
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action...
Moderate
Unreviewed
CVE-2022-1422
was published
Jun 9, 2022
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter...
Moderate
Unreviewed
CVE-2022-1005
was published
Jun 9, 2022
Cross-site Scripting in RosarioSIS
Moderate
CVE-2022-1997
was published
for
francoisjacquet/rosariosis
(Composer)
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the...
Critical
Unreviewed
CVE-2022-30925
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the...
Critical
Unreviewed
CVE-2022-30923
was published
Jun 9, 2022
A vulnerability was found in OSM Lab show-me-the-way. It has been rated as problematic. This...
Moderate
Unreviewed
CVE-2018-25064
was published
Jan 5, 2023
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software...
Moderate
Unreviewed
CVE-2016-4741
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89...
Moderate
Unreviewed
CVE-2016-5148
was published
May 17, 2022
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker...
Moderate
Unreviewed
CVE-2022-1421
was published
Jun 9, 2022
Printing UIKit in Apple iOS before 10 mishandles environment variables, which allows local users...
Low
Unreviewed
CVE-2016-4749
was published
May 17, 2022
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows...
High
Unreviewed
CVE-2010-1496
was published
May 17, 2022
Das U-Boot 2022.01 has a Buffer Overflow, a different issue than CVE-2022-30552.
High
Unreviewed
CVE-2022-30790
was published
Jun 9, 2022
A flaw found in function dataWindowForTile() of IlmImf/ImfTiledMisc.cpp. An attacker who is able...
Moderate
Unreviewed
CVE-2021-20303
was published
Mar 5, 2022
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access...
High
Unreviewed
CVE-2022-43844
was published
Jan 5, 2023
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise...
High
Unreviewed
CVE-2022-43519
was published
Jan 5, 2023
osagent.exe in Borland VisiBroker Smart Agent 08.00.00.C1.03 and earlier allows remote attackers...
Moderate
Unreviewed
CVE-2008-7127
was published
May 17, 2022
Unspecified vulnerability in DB2 Monitoring Console 2.2.4 and earlier allows remote attackers to...
Moderate
Unreviewed
CVE-2008-7130
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability in Live 5.x before 5.x-0.1, a module for Drupal,...
Moderate
Unreviewed
CVE-2008-7151
was published
May 17, 2022
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files,...
High
Unreviewed
CVE-2008-7102
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API