GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,262
Erlang
31
GitHub Actions
21
Go
2,030
Maven
5,000+
npm
3,732
NuGet
662
pip
3,409
Pub
12
RubyGems
891
Rust
865
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
311 advisories
Filter by severity
An issue was discovered on D-Link DIR-878 1.12B01 devices. Because strncpy is misused, there is a...
Critical
Unreviewed
CVE-2019-9125
was published
May 13, 2022
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request....
Critical
Unreviewed
CVE-2019-10041
was published
May 13, 2022
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request....
Critical
Unreviewed
CVE-2019-10040
was published
May 13, 2022
The D-Link DIR-816 A2 1.11 router only checks the random token when authorizing a goform request....
Critical
Unreviewed
CVE-2019-10039
was published
May 13, 2022
SAP Cloud Connector, before version 2.11.3, does not perform any authentication checks for...
Critical
Unreviewed
CVE-2019-0246
was published
May 13, 2022
Under certain circumstances, SAP HANA Extended Application Services, advanced model (XS advanced)...
Critical
Unreviewed
CVE-2019-0261
was published
May 13, 2022
A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption...
Critical
Unreviewed
CVE-2018-6223
was published
May 13, 2022
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and...
Critical
Unreviewed
CVE-2018-19248
was published
May 13, 2022
Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow...
Critical
Unreviewed
CVE-2018-13114
was published
May 13, 2022
A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco...
Critical
Unreviewed
CVE-2018-0127
was published
May 13, 2022
A design flaw issue was found in the Red Hat OpenStack Platform director use of TripleO to enable...
Critical
Unreviewed
CVE-2017-2637
was published
May 13, 2022
Summer Baby Zoom Wifi Monitor & Internet Viewing System allows remote attackers to bypass...
Critical
Unreviewed
CVE-2015-2888
was published
May 13, 2022
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x...
Critical
Unreviewed
CVE-2022-1388
was published
May 6, 2022
Multiple Version of TRUMPF TruTops products expose a service function without necessary...
Critical
Unreviewed
CVE-2022-1300
was published
May 3, 2022
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote...
Critical
Unreviewed
CVE-2022-28719
was published
Apr 29, 2022
xlockmore 5.13 allows potential xlock bypass when FVWM switches to the same virtual desktop as a...
Critical
Unreviewed
CVE-2006-0062
was published
Apr 21, 2022
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows...
Critical
Unreviewed
CVE-2022-0992
was published
Apr 20, 2022
The SiteGround Security plugin for WordPress is vulnerable to authentication bypass that allows...
Critical
Unreviewed
CVE-2022-0993
was published
Apr 20, 2022
AVEVA System Platform versions 2017 through 2020 R2 P01 does not perform any authentication for...
Critical
Unreviewed
CVE-2021-33008
was published
Apr 5, 2022
In Totolink A3100R V5.9c.4577, multiple pages can be read by curl or Burp Suite without...
Critical
Unreviewed
CVE-2021-46009
was published
Apr 1, 2022
A vulnerability is in the 'wx.html' page of the WAVLINK AC1200, version WAVLINK-A42W-1.27.6...
Critical
Unreviewed
CVE-2021-44259
was published
Mar 18, 2022
Veeam Backup & Replication 10.x and 11.x has Incorrect Access Control (issue 1 of 2).
Critical
Unreviewed
CVE-2022-26501
was published
Mar 18, 2022
Axeda agent (All versions) and Axeda Desktop Server for Windows (All versions) may allow an...
Critical
Unreviewed
CVE-2022-25247
was published
Mar 17, 2022
When connecting to a certain port Axeda agent (All versions) and Axeda Desktop Server for Windows...
Critical
Unreviewed
CVE-2022-25251
was published
Mar 17, 2022
Power Line Communications PLC4TRUCKS J2497 trailer brake controllers implement diagnostic...
Critical
Unreviewed
CVE-2022-25922
was published
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API