GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,274
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,419
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
148 advisories
Filter by severity
Cache Poisoning issue exists in DNS Response Rate Limiting.
Moderate
Unreviewed
CVE-2013-5661
was published
May 5, 2022
In JetBrains YouTrack before 2024.1.25893 creation comments on behalf of an arbitrary user in...
Moderate
Unreviewed
CVE-2024-28228
was published
Mar 7, 2024
Authentication Bypass by Spoofing in github.com/greenpau/caddy-security
Moderate
CVE-2024-21494
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a...
Moderate
Unreviewed
CVE-2023-4001
was published
Jan 15, 2024
Authentication Bypass by Spoofing vulnerability in Snow Software Snow Inventory Agent on Windows...
Moderate
Unreviewed
CVE-2023-7169
was published
Feb 8, 2024
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2....
Moderate
Unreviewed
CVE-2021-32076
was published
May 24, 2022
ELAN Match-on-Chip FPR solution has design fault about potential risk of valid SID leakage and...
Moderate
Unreviewed
CVE-2024-0454
was published
Jan 12, 2024
Multiple Cisco products are affected by a vulnerability in Snort access control policies that...
Moderate
Unreviewed
CVE-2023-20246
was published
Nov 1, 2023
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20256
was published
Nov 1, 2023
Multiple vulnerabilities in the per-user-override feature of Cisco Adaptive Security Appliance ...
Moderate
Unreviewed
CVE-2023-20245
was published
Nov 1, 2023
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local...
Moderate
Unreviewed
CVE-2023-6044
was published
Jan 19, 2024
Windows Hello Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2021-34466
was published
May 24, 2022
Header spoofing in caddy-geo-ip
Moderate
CVE-2023-50463
was published
for
github.com/shift72/caddy-geo-ip
(Go)
Dec 11, 2023
A spoofing vulnerability exists when Microsoft Browsers improperly handle browser cookies, aka ...
Moderate
Unreviewed
CVE-2019-1357
was published
May 24, 2022
A spoofing vulnerability exists when Microsoft Browsers does not properly parse HTTP content, aka...
Moderate
Unreviewed
CVE-2019-0608
was published
May 24, 2022
Microsoft Edge (Chromium-based) Spoofing Vulnerability
Moderate
Unreviewed
CVE-2023-21794
was published
Feb 14, 2023
Electron vulnerable to URL spoofing via PDFium
Moderate
CVE-2017-1000424
was published
for
Electron
(npm)
May 13, 2022
OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide...
Moderate
Unreviewed
CVE-2020-12272
was published
May 24, 2022
Due to a bug in the handling of the communication between the client and server, it was possible...
Moderate
Unreviewed
CVE-2022-35629
was published
Jul 30, 2022
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password
Moderate
CVE-2022-2368
was published
for
microweber/microweber
(Composer)
Jul 12, 2022
The Formidable Forms WordPress plugin before 6.1 uses several potentially untrusted headers to...
Moderate
Unreviewed
CVE-2023-0816
was published
Mar 27, 2023
A vulnerability exists in the garbage collection mechanism of atomic-openshift. An attacker able...
Moderate
Unreviewed
CVE-2019-3884
was published
May 24, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard or ARP inspection can be bypassed...
Moderate
Unreviewed
CVE-2021-27853
was published
Sep 28, 2022
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP...
Moderate
Unreviewed
CVE-2021-27861
was published
Sep 28, 2022
ProTip!
Advisories are also available from the
GraphQL API