GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,732
Erlang
35
GitHub Actions
29
Go
2,310
Maven
5,000+
npm
3,949
NuGet
711
pip
3,728
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
164 advisories
Filter by severity
A CORS Misconfiguration in the web-based management allows a malicious third party webserver to...
Moderate
Unreviewed
CVE-2022-45139
was published
Feb 27, 2023
Inappropriate implementation in in Permission prompts in Google Chrome on Windows prior to 109.0...
Moderate
Unreviewed
CVE-2023-0132
was published
Jan 10, 2023
Zip4j Origin Validation Error
Moderate
CVE-2023-22899
was published
for
net.lingala.zip4j:zip4j
(Maven)
Jan 10, 2023
Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have...
Moderate
Unreviewed
CVE-2022-22757
was published
Dec 22, 2022
When viewing an email message A, which contains an attached message B, where B is encrypted or...
Moderate
Unreviewed
CVE-2022-1520
was published
Dec 22, 2022
The Performance API did not properly hide the fact whether a request cross-origin resource has...
Moderate
Unreviewed
CVE-2022-29915
was published
Dec 22, 2022
An attacker could have abused XSLT error handling to associate attacker-controlled content with...
Moderate
Unreviewed
CVE-2022-38472
was published
Dec 22, 2022
IBM Robotic Process Automation 21.0.0, 21.0.1, 21.0.2, 21.0.3, and 21.0.4 is vulnerable to cross...
Moderate
Unreviewed
CVE-2022-41294
was published
Oct 6, 2022
An origin validation error vulnerability in Trend Micro Apex One and Apex One as a Service could...
Moderate
Unreviewed
CVE-2022-40140
was published
Sep 20, 2022
Inappropriate implementation in Input in Google Chrome prior to 101.0.4951.41 allowed a remote...
Moderate
Unreviewed
CVE-2022-1497
was published
Jul 27, 2022
The authentication mechanism used by voters to activate a voting session on the tested version of...
Moderate
Unreviewed
CVE-2022-1747
was published
Jun 25, 2022
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6),...
Moderate
Unreviewed
CVE-2022-30228
was published
Jun 15, 2022
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension...
Moderate
Unreviewed
CVE-2019-1413
was published
May 24, 2022
Through use of reportValidity() and window.open(), a plain-text validation message could have...
Moderate
Unreviewed
CVE-2021-38497
was published
May 24, 2022
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54...
Moderate
Unreviewed
CVE-2021-37966
was published
May 24, 2022
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote...
Moderate
Unreviewed
CVE-2021-37971
was published
May 24, 2022
Incorrect security UI in Navigation in Google Chrome on Android prior to 92.0.4515.131 allowed a...
Moderate
Unreviewed
CVE-2021-30596
was published
May 24, 2022
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a...
Moderate
Unreviewed
CVE-2021-21229
was published
May 24, 2022
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed...
Moderate
Unreviewed
CVE-2021-21211
was published
May 24, 2022
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote...
Moderate
Unreviewed
CVE-2021-21209
was published
May 24, 2022
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS...
Moderate
Unreviewed
CVE-2021-28048
was published
May 24, 2022
An Origin Validation Error vulnerability in Bitdefender Safepay allows an attacker to manipulate...
Moderate
Unreviewed
CVE-2020-15734
was published
May 24, 2022
A malicious extension with the 'search' permission could have installed a new search engine whose...
Moderate
Unreviewed
CVE-2021-23986
was published
May 24, 2022
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a...
Moderate
Unreviewed
CVE-2021-21183
was published
May 24, 2022
Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a...
Moderate
Unreviewed
CVE-2021-21184
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API