GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
276 advisories
Filter by severity
Wildfly-Core user account mismanagement
High
CVE-2021-3717
was published
for
org.wildfly.core:wildfly-core-parent
(Maven)
May 25, 2022
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence...
Moderate
Unreviewed
CVE-2021-31600
was published
May 24, 2022
NETSCOUT Systems nGeniusONE 6.3.0 build 1196 allows Arbitrary File Read operations via the...
Moderate
Unreviewed
CVE-2021-35203
was published
May 24, 2022
Hitachi Content Platform Anywhere (HCP-AW) 4.4.5 and later allows information disclosure. If...
Moderate
Unreviewed
CVE-2021-41573
was published
May 24, 2022
The vCenter Server contains multiple local privilege escalation vulnerabilities due to improper...
High
Unreviewed
CVE-2021-22015
was published
May 24, 2022
A local file inclusion vulnerability in ExpertPDF 9.5.0 through 14.1.0 allows attackers to read...
High
Unreviewed
CVE-2020-35340
was published
May 24, 2022
Emby Server is a personal media server with apps on many devices. In Emby Server on Windows there...
High
Unreviewed
CVE-2021-32833
was published
May 24, 2022
An improper access control vulnerability in sspInit() in BlockchainTZService prior to SMR Sep...
Moderate
Unreviewed
CVE-2021-25459
was published
May 24, 2022
A vulnerability in the web UI for Cisco Nexus Insights could allow an authenticated, remote...
Moderate
Unreviewed
CVE-2021-34765
was published
May 24, 2022
The function AdminGetFirstFileContentByFilePath in MIK.starlight 7.9.5.24363 allows (by design)...
Moderate
Unreviewed
CVE-2021-36233
was published
May 24, 2022
An information disclosure vulnerability in rConfig 3.9.5 has been fixed for version 3.9.6. This...
Moderate
Unreviewed
CVE-2020-25351
was published
May 24, 2022
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access...
High
Unreviewed
CVE-2020-22124
was published
May 24, 2022
In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
High
Unreviewed
CVE-2021-38711
was published
May 24, 2022
Nagios XI before version 5.8.5 is vulnerable to local file inclusion through improper limitation...
High
Unreviewed
CVE-2021-37348
was published
May 24, 2022
Dell DBUtilDrv2.sys driver (versions 2.5 and 2.6) contains an insufficient access control...
High
Unreviewed
CVE-2021-36276
was published
May 24, 2022
If Thunderbird was configured to use STARTTLS for an IMAP connection, and an attacker injected...
Moderate
Unreviewed
CVE-2021-29969
was published
May 24, 2022
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
High
Unreviewed
CVE-2021-36763
was published
May 24, 2022
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an...
High
Unreviewed
CVE-2021-33359
was published
May 24, 2022
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4...
High
Unreviewed
CVE-2021-31831
was published
May 24, 2022
It has been discovered that redhat-certification does not restrict file access in the /update...
Critical
Unreviewed
CVE-2018-10867
was published
May 24, 2022
It has been discovered that redhat-certification is not properly configured and it lists all...
High
Unreviewed
CVE-2018-10863
was published
May 24, 2022
In InvoicePlane 1.5.11 a misconfigured web server allows unauthenticated directory listing and...
High
Unreviewed
CVE-2021-29024
was published
May 24, 2022
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2021-1512
was published
May 24, 2022
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an...
Moderate
Unreviewed
CVE-2021-1256
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API