GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
337 advisories
Filter by severity
An issue was discovered in HTCondor before 8.8.15, 9.0.x before 9.0.4, and 9.1.x before 9.1.2....
High
Unreviewed
CVE-2021-45101
was published
Dec 17, 2021
Insecure permissions on user namespace / fakeroot temporary rootfs in Singularity
High
CVE-2020-25039
was published
for
github.com/sylabs/singularity
(Go)
Dec 20, 2021
An Improper Access Control Vulnerability in the SMA100 series leads to multiple restricted...
High
Unreviewed
CVE-2021-20050
was published
Dec 24, 2021
An arbitrary file download vulnerability in jeecg v3.8 allows attackers to access sensitive files...
High
Unreviewed
CVE-2020-20948
was published
Dec 28, 2021
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of...
High
Unreviewed
CVE-2021-36723
was published
Dec 30, 2021
Go before 1.16.12 and 1.17.x before 1.17.5 on UNIX allows write operations to an unintended file...
High
Unreviewed
CVE-2021-44717
was published
Jan 2, 2022
An issue was discovered in BS_RCIO64.sys in Biostar RACING GT Evo 2.1.1905.1700. A low-integrity...
High
Unreviewed
CVE-2021-44852
was published
Jan 2, 2022
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this...
High
Unreviewed
CVE-2021-39969
was published
Jan 4, 2022
MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability...
High
Unreviewed
CVE-2021-39972
was published
Jan 4, 2022
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this...
High
Unreviewed
CVE-2021-37133
was published
Jan 4, 2022
Improper access control while doing XPU re-configuration dynamically can lead to unauthorized...
High
Unreviewed
CVE-2021-30276
was published
Jan 4, 2022
Abomonation transmutes &T to and from &[u8] without sufficient constraints
High
CVE-2021-45708
was published
for
abomonation
(Rust)
Jan 6, 2022
The distributed data service component has a vulnerability in data access control. Successful...
High
Unreviewed
CVE-2021-40005
was published
Jan 11, 2022
Windows GDI Information Disclosure Vulnerability.
High
Unreviewed
CVE-2022-21904
was published
Jan 12, 2022
Windows GDI+ Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-21915.
High
Unreviewed
CVE-2022-21880
was published
Jan 12, 2022
Agent-to-controller security bypass in Jenkins Debian Package Builder Plugin
High
CVE-2022-23118
was published
for
ru.yandex.jenkins.plugins.debuilder:debian-package-builder
(Maven)
Jan 13, 2022
pgjdbc Does Not Check Class Instantiation when providing Plugin Classes
High
CVE-2022-21724
was published
for
org.postgresql:postgresql
(Maven)
Feb 2, 2022
In DataEase v1.6.1, an authenticated user can gain unauthorized access to all user information...
High
Unreviewed
CVE-2022-23331
was published
Feb 9, 2022
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct...
High
Unreviewed
CVE-2021-42641
was published
Feb 9, 2022
Insecure temporary file in Tensorflow
High
CVE-2022-23563
was published
for
tensorflow
(pip)
Feb 9, 2022
Windows Services for NFS ONCRPC XDR Driver Information Disclosure Vulnerability.
High
Unreviewed
CVE-2022-21993
was published
Feb 10, 2022
Thinfinity VirtualUI 2.1.28.0, 2.1.32.1 and 2.5.26.2, fixed in version 3.0 is affected by an...
High
Unreviewed
CVE-2021-46354
was published
Feb 10, 2022
The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted...
High
Unreviewed
CVE-2022-24975
was published
Feb 12, 2022
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of...
High
Unreviewed
CVE-2021-22785
was published
Feb 12, 2022
Exposure of Resource to Wrong Sphere in Drupal Core
High
CVE-2020-13670
was published
for
drupal/core
(Composer)
Feb 12, 2022
ProTip!
Advisories are also available from the
GraphQL API