GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
147 advisories
Filter by severity
ZZ Inc. KeyMouse Windows 3.08 and prior is affected by a remote code execution vulnerability...
High
Unreviewed
CVE-2022-24644
was published
Mar 11, 2022
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check...
High
Unreviewed
CVE-2022-28944
was published
May 24, 2022
An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check,...
High
Unreviewed
CVE-2021-27574
was published
May 24, 2022
Honeywell Experion PKS Safety Manager (SM and FSC) through 2022-05-06 has Insufficient...
Critical
Unreviewed
CVE-2022-30315
was published
Jul 29, 2022
An arbitrary file download vulnerability in the downloadAction() function of Penta Security...
Moderate
Unreviewed
CVE-2022-31324
was published
Sep 14, 2022
The Zoom Client for Meetings for Windows before version 5.10.0 and Zoom Rooms for Conference Room...
High
Unreviewed
CVE-2022-22786
was published
May 19, 2022
In Tipask < 3.5.9, path parameters entered by the user are not validated when downloading...
Moderate
Unreviewed
CVE-2021-41714
was published
May 24, 2022
Rapid7 Nexpose versions prior to 6.6.172 failed to reliably validate the authenticity of update...
Moderate
Unreviewed
CVE-2022-4261
was published
Dec 8, 2022
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its...
High
Unreviewed
CVE-2019-7229
was published
May 24, 2022
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via...
High
Unreviewed
CVE-2021-45027
was published
Sep 2, 2022
Certain General Electric Renewable Energy products download firmware without an integrity check....
Critical
Unreviewed
CVE-2022-24117
was published
Dec 26, 2022
Barco wePresent WiPG-1600W devices download code without an Integrity Check. Affected Version(s):...
Critical
Unreviewed
CVE-2020-28332
was published
May 24, 2022
AppImage appimaged before 1.0.3 does not properly check whether a downloaded file is a valid...
Moderate
Unreviewed
CVE-2020-25266
was published
May 24, 2022
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A...
High
Unreviewed
CVE-2021-33879
was published
May 24, 2022
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC...
High
Unreviewed
CVE-2021-38588
was published
May 24, 2022
A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur...
Moderate
Unreviewed
CVE-2021-30669
was published
May 24, 2022
This issue was addressed with improved handling of file metadata. This issue is fixed in macOS...
Moderate
Unreviewed
CVE-2021-30658
was published
May 24, 2022
Download of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd...
Critical
Unreviewed
CVE-2020-7873
was published
May 24, 2022
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of...
High
Unreviewed
CVE-2020-7874
was published
May 24, 2022
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote...
High
Unreviewed
CVE-2020-7875
was published
May 24, 2022
A remote file download issue can occur in some capabilities of Esri ArcGIS Server web services...
Moderate
Unreviewed
CVE-2022-38199
was published
Oct 25, 2022
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on...
High
Unreviewed
CVE-2020-28213
was published
May 24, 2022
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the...
High
Unreviewed
CVE-2022-36671
was published
Sep 2, 2022
An exploitable privilege escalation vulnerability exists in the Shimo VPN helper service due to...
High
Unreviewed
CVE-2018-4009
was published
May 13, 2022
The Miss Marple Updater Service in COMPAREX Miss Marple Enterprise Edition before 2.0 allows...
High
Unreviewed
CVE-2018-19234
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API