GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an...
Critical
Unreviewed
CVE-2023-3325
was published
Jun 20, 2023
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to...
High
Unreviewed
CVE-2023-30759
was published
Jun 19, 2023
Insufficient verification of data authenticity in Zoom for Windows clients before 5.14.0 may...
High
Unreviewed
CVE-2023-34113
was published
Jun 13, 2023
The Brizy Page Builder plugin for WordPress is vulnerable to IP Address Spoofing in versions up...
Moderate
Unreviewed
CVE-2023-2897
was published
Jun 9, 2023
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto...
High
Unreviewed
CVE-2023-2866
was published
Jun 7, 2023
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of...
Critical
Unreviewed
CVE-2023-2987
was published
May 31, 2023
Snap One OvrC Pro devices versions 7.2 and prior do not validate firmware...
Critical
Unreviewed
CVE-2023-28386
was published
May 22, 2023
Jenkins SAML Single Sign On(SSO) Plugin missing hostname validation
Moderate
CVE-2023-32993
was published
for
io.jenkins.plugins:miniorange-saml-sp
(Maven)
May 16, 2023
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2023-31502
was published
May 12, 2023
In modem, there is a possible missing verification of HashMME value in Security Mode Command....
Moderate
Unreviewed
CVE-2022-44420
was published
May 9, 2023
AMI MegaRAC SPx12 and SPx13 devices have Insufficient Verification of Data Authenticity.
Critical
Unreviewed
CVE-2023-28863
was published
Apr 18, 2023
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded...
Critical
Unreviewed
CVE-2023-27748
was published
Apr 13, 2023
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
High
Unreviewed
CVE-2023-26467
was published
Apr 11, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27979
was published
Mar 21, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27977
was published
Mar 21, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27982
was published
Mar 21, 2023
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could...
Moderate
Unreviewed
CVE-2023-0350
was published
Mar 13, 2023
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the...
High
Unreviewed
CVE-2017-20180
was published
Mar 6, 2023
Keycloak vulnerable to user impersonation via stolen UUID code
High
CVE-2023-0264
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 2, 2023
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30...
Moderate
Unreviewed
CVE-2023-21441
was published
Feb 9, 2023
Payment information sent to PayPal not necessarily identical to created order
High
CVE-2023-23941
was published
for
swag/paypal
(Composer)
Feb 3, 2023
OpenZeppelin Contracts contains Improper Verification of Cryptographic Signature
Moderate
CVE-2023-23940
was published
for
openzeppelin-cairo-contracts
(pip)
Feb 2, 2023
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network ...
High
Unreviewed
CVE-2023-22315
was published
Jan 31, 2023
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a...
Moderate
Unreviewed
CVE-2021-26396
was published
Jan 11, 2023
go-resolver vulnerable to attacker-controlled domains due to unvalidated RRSIG RRs
High
CVE-2022-3346
was published
for
github.com/peterzen/goresolver
(Go)
Dec 28, 2022
ProTip!
Advisories are also available from the
GraphQL API