GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
43 advisories
Filter by severity
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the...
High
Unreviewed
CVE-2024-6788
was published
Aug 13, 2024
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. It performs...
High
Unreviewed
CVE-2019-20470
was published
May 24, 2022
An authentication bypass vulnerability exists in the CiRpcAccepted() functionality of SoftEther...
High
Unreviewed
CVE-2023-27516
was published
Oct 12, 2023
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a possible way to access adb...
High
Unreviewed
CVE-2023-35689
was published
Aug 15, 2023
Active Debug Code vulnerability in Mitsubishi Electric Corporation MELSEC WS Series WS0-GETH00200...
High
Unreviewed
CVE-2023-1618
was published
May 19, 2023
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main...
High
Unreviewed
CVE-2018-20052
was published
May 24, 2022
In the configuration of NFC modules on certain devices, there is a possible failure to...
High
Unreviewed
CVE-2019-2041
was published
May 24, 2022
ETIC Telecom RAS versions 4.7.0 and prior the web management portal authentication disabled by...
High
Unreviewed
CVE-2023-3453
was published
Aug 24, 2023
A spoofing vulnerability manifests in Microsoft Xamarin.Forms due to the default settings on...
High
Unreviewed
CVE-2020-16873
was published
May 24, 2022
In multiple products of CODESYS v3 in multiple versions a remote low privileged user could...
High
Unreviewed
CVE-2022-4224
was published
Mar 23, 2023
A vulnerability in the firmware of the Cisco UCS C-Series Rack Servers could allow an...
High
Unreviewed
CVE-2019-1950
was published
May 24, 2022
Tinyproxy commit 84f203f and earlier does not process HTTP request lines in the process_request()...
High
Unreviewed
CVE-2022-40468
was published
Sep 20, 2022
A regression exists in the Linux Kernel within KVM: nVMX that allowed for speculative execution...
High
Unreviewed
CVE-2022-2196
was published
Jan 9, 2023
In JetBrains IntelliJ IDEA before 2023.1 the bundled version of Chromium wasn't sandboxed.
High
Unreviewed
CVE-2022-48432
was published
Mar 29, 2023
The default configuration of broker.conf in Red Hat OpenShift Enterprise 2.x before 2.1 has a...
High
Unreviewed
CVE-2014-0234
was published
May 17, 2022
A flaw was found in Ansible Tower, versions 3.6.x before 3.6.2 and 3.5.x before 3.5.3, where...
High
Unreviewed
CVE-2019-19340
was published
May 24, 2022
dcc_curr_list is initialized with a default invalid value that is expected to be programmed by...
High
Unreviewed
CVE-2018-5841
was published
May 13, 2022
Installation tool IPDT (Intel Processor Diagnostic Tool) 4.1.0.24 sets permissions of installed...
High
Unreviewed
CVE-2018-3667
was published
May 13, 2022
Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition...
High
Unreviewed
CVE-2018-20402
was published
May 13, 2022
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the...
High
Unreviewed
CVE-2017-9137
was published
May 13, 2022
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an...
High
Unreviewed
CVE-2017-6689
was published
May 13, 2022
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote...
High
Unreviewed
CVE-2017-6684
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Element Manager could allow an authenticated,...
High
Unreviewed
CVE-2017-6692
was published
May 13, 2022
A vulnerability in Cisco Elastic Services Controllers could allow an authenticated, remote...
High
Unreviewed
CVE-2017-6688
was published
May 13, 2022
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated,...
High
Unreviewed
CVE-2017-6685
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API