GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,715
Erlang
34
GitHub Actions
28
Go
2,302
Maven
5,000+
npm
3,946
NuGet
711
pip
3,716
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
164 advisories
Filter by severity
Through use of reportValidity() and window.open(), a plain-text validation message could have...
Moderate
Unreviewed
CVE-2021-38497
was published
May 24, 2022
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension...
Moderate
Unreviewed
CVE-2019-1413
was published
May 24, 2022
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6),...
Moderate
Unreviewed
CVE-2022-30228
was published
Jun 15, 2022
The authentication mechanism used by voters to activate a voting session on the tested version of...
Moderate
Unreviewed
CVE-2022-1747
was published
Jun 25, 2022
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote...
Moderate
Unreviewed
CVE-2022-1497
was published
Jul 27, 2022
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could...
Moderate
Unreviewed
CVE-2022-40140
was published
Sep 20, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross...
Moderate
Unreviewed
CVE-2022-41294
was published
Oct 6, 2022
An attacker could have abused XSLT error handling to associate attacker-controlled content with...
Moderate
Unreviewed
CVE-2022-38472
was published
Dec 22, 2022
The Performance API did not properly hide the fact whether a request cross-origin resource has...
Moderate
Unreviewed
CVE-2022-29915
was published
Dec 22, 2022
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have...
Moderate
Unreviewed
CVE-2022-22757
was published
Dec 22, 2022
When viewing an email message A, which contains an attached message B, where B is encrypted or...
Moderate
Unreviewed
CVE-2022-1520
was published
Dec 22, 2022
Zip4j Origin Validation Error
Moderate
CVE-2023-22899
was published
for
net.lingala.zip4j:zip4j
(Maven)
Jan 10, 2023
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0...
Moderate
Unreviewed
CVE-2023-0132
was published
Jan 10, 2023
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to...
Moderate
Unreviewed
CVE-2022-45139
was published
Feb 27, 2023
Improper access control in Subscriptions Folder path filter in Devolutions Server 2023.1.1 and...
Moderate
Unreviewed
CVE-2023-2445
was published
May 2, 2023
Zammad 5.3.x (Fixed 5.4.0) is vulnerable to Incorrect Access Control. An authenticated attacker...
Moderate
Unreviewed
CVE-2023-29867
was published
May 2, 2023
Zammad 5.3.x (Fixed in 5.4.0) is vulnerable to Incorrect Access Control. An authenticated...
Moderate
Unreviewed
CVE-2023-29868
was published
May 2, 2023
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13...
Moderate
Unreviewed
CVE-2023-27932
was published
May 8, 2023
A logic issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3,...
Moderate
Unreviewed
CVE-2023-27962
was published
May 8, 2023
A vulnerability has been discovered in Rocket.Chat, where messages can be hidden regardless of...
Moderate
Unreviewed
CVE-2023-28318
was published
May 10, 2023
Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation
Moderate
CVE-2023-32993
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
May 16, 2023
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via...
Moderate
Unreviewed
CVE-2023-2886
was published
May 25, 2023
Stormshield Endpoint Security 2.3.0 through 2.3.2 has Incorrect Access Control: authenticated...
Moderate
Unreviewed
CVE-2023-23561
was published
May 30, 2023
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab...
Moderate
Unreviewed
CVE-2023-23601
was published
Jun 2, 2023
Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user...
Moderate
Unreviewed
CVE-2023-28164
was published
Jun 2, 2023
ProTip!
Advisories are also available from the
GraphQL API