GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,328
Maven
5,000+
npm
3,965
NuGet
712
pip
3,745
Pub
12
RubyGems
921
Rust
974
Swift
38
Unreviewed advisories
All unreviewed
5,000+
3,804 advisories
Filter by severity
A potential vulnerability in Splunk Enterprise's implementation of DUO MFA allows for bypassing...
High
Unreviewed
CVE-2021-26253
was published
May 7, 2022
Certain NETGEAR devices are affected by authentication bypass. This affects RBK852 before 3.2.17...
Critical
Unreviewed
CVE-2021-29066
was published
May 24, 2022
An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. Autoblocks for...
Critical
Unreviewed
CVE-2021-36128
was published
May 24, 2022
Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an...
High
Unreviewed
CVE-2021-35941
was published
May 24, 2022
In doNotification of AccountManagerService.java, there is a possible permission bypass due to an...
Moderate
Unreviewed
CVE-2021-0572
was published
May 24, 2022
In ActivityTaskManagerService.startActivity() and AppTaskImpl.startActivity() of...
High
Unreviewed
CVE-2021-0571
was published
May 24, 2022
Improper Authentication in Apache Hadoop
Low
CVE-2013-2192
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
XWiki Platform Old Core vulnerable to Authentication Bypass Using the Login Action
High
CVE-2022-36092
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Sep 16, 2022
TYPO3 CMS missing check for expiration time of password reset token for backend users
Moderate
CVE-2022-36106
was published
for
typo3/cms
(Composer)
Sep 16, 2022
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and...
Critical
Unreviewed
CVE-2020-13963
was published
May 24, 2022
The vSphere Client (HTML5) contains a vulnerability in a vSphere authentication mechanism for the...
Critical
Unreviewed
CVE-2021-21986
was published
May 24, 2022
Improper access control vulnerability in Phone Messages of Cybozu Office 10.0.0 to 10.8.4 allows...
Moderate
Unreviewed
CVE-2021-20630
was published
May 24, 2022
The impacted products, when configured to use SSO, are affected by an improper authentication...
Critical
Unreviewed
CVE-2021-43935
was published
Dec 16, 2021
A vulnerability in the web application of Cisco Common Services Platform Collector (CSPC) could...
Moderate
Unreviewed
CVE-2021-40130
was published
Nov 20, 2021
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation...
Critical
Unreviewed
CVE-2021-3325
was published
May 24, 2022
Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 88.0.4324...
High
Unreviewed
CVE-2021-21125
was published
May 24, 2022
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed...
Moderate
Unreviewed
CVE-2021-21129
was published
May 24, 2022
An authentication issue was addressed with improved state management. This issue is fixed in...
High
Unreviewed
CVE-2020-29633
was published
May 24, 2022
Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a...
Moderate
Unreviewed
CVE-2021-21189
was published
May 24, 2022
NETGEAR RBR850 devices before 3.2.10.11 are affected by authentication bypass.
Critical
Unreviewed
CVE-2021-29065
was published
May 24, 2022
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allow Authentication...
Critical
Unreviewed
CVE-2020-25218
was published
May 24, 2022
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7,...
Critical
Unreviewed
CVE-2021-27215
was published
May 24, 2022
Insufficient policy enforcement in extensions in Google Chrome prior to 88.0.4324.96 allowed a...
High
Unreviewed
CVE-2021-21127
was published
May 24, 2022
Insufficient policy enforcement in File System API in Google Chrome prior to 88.0.4324.96 allowed...
Moderate
Unreviewed
CVE-2021-21141
was published
May 24, 2022
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. Client...
Moderate
Unreviewed
CVE-2020-25251
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API