GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,715
Erlang
34
GitHub Actions
28
Go
2,302
Maven
5,000+
npm
3,946
NuGet
711
pip
3,716
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
114 advisories
Filter by severity
An issue was discovered in Network Optix NxCloud before 23.1.0.40440. It was possible to add a...
High
Unreviewed
CVE-2023-6263
was published
Nov 22, 2023
Authentication bypass vulnerability, the exploitation of which could allow a local attacker to...
High
Unreviewed
CVE-2023-3103
was published
Nov 22, 2023
omniauth-apple allows attacker to fake their email address during authentication
High
CVE-2020-26254
was published
for
omniauth-apple
(RubyGems)
Dec 8, 2020
Withdrawn Advisory: Node.js Inspector RCE via DNS Rebinding
High
CVE-2018-7160
was published
for
node-inspector
(npm)
May 13, 2022
•
withdrawn
A flaw was found in Samba. The KDC accepts kpasswd requests encrypted with any key known to it....
High
Unreviewed
CVE-2022-32744
was published
Aug 26, 2022
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault
High
CVE-2020-16250
was published
for
github.com/hashicorp/vault
(Go)
Aug 2, 2021
passport-wsfed-saml2 vulnerable to Signature Bypass in SAML2 token
High
CVE-2017-16897
was published
for
passport-wsfed-saml2
(npm)
Jun 21, 2023
Duplicate advisory: High severity vulnerability that affects passport-wsfed-saml2
High
GHSA-7fpw-cfc4-3p2c
was published
for
passport-wsfed-saml2
(npm)
Dec 28, 2017
•
withdrawn
The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in...
High
Unreviewed
CVE-2022-1762
was published
Jun 14, 2022
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass...
High
Unreviewed
CVE-2019-16378
was published
May 24, 2022
The User Activity WordPress plugin through 1.0.1 checks headers such as the X-Forwarded-For to...
High
Unreviewed
CVE-2022-4550
was published
Feb 27, 2023
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that allows for...
High
Unreviewed
CVE-2019-15022
was published
May 24, 2022
Authentication Bypass by Spoofing vulnerability in Mitsubishi Electric Corporation GOT2000 Series...
High
Unreviewed
CVE-2022-40269
was published
Feb 2, 2023
The FluentAuth WordPress plugin before 1.0.2 prioritizes getting a visitor's IP address from...
High
Unreviewed
CVE-2022-4746
was published
Jan 23, 2023
The WP Limit Login Attempts WordPress plugin through 2.6.4 prioritizes getting a visitor's IP...
High
Unreviewed
CVE-2022-4303
was published
Jan 23, 2023
Parse Server option `masterKeyIps` vulnerability to IP spoofing
High
CVE-2023-22474
was published
for
parse-server
(npm)
Jan 31, 2023
MailMate before 1.11.3 mishandles a suspicious HTML/MIME structure in a signed/encrypted email.
High
Unreviewed
CVE-2018-15588
was published
May 13, 2022
An issue was discovered in Veritas NetBackup 8.0 and earlier and NetBackup Appliance 3.0 and...
High
Unreviewed
CVE-2017-6405
was published
May 13, 2022
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2...
High
Unreviewed
CVE-2017-18190
was published
May 13, 2022
MetInfo through 5.3.17 accepts the same CAPTCHA response for 120 seconds, which makes it easier...
High
Unreviewed
CVE-2017-11717
was published
May 13, 2022
anji-plus AJ-Report 0.9.8.6 allows remote attackers to bypass login authentication by spoofing...
High
Unreviewed
CVE-2022-42983
was published
Oct 17, 2022
HTTP Method Spoofing
High
CVE-2021-43807
was published
for
org.opencastproject:opencast-common
(Maven)
Dec 14, 2021
SAP NetWeaver Process Integration (Adapter Engine), fixed in versions 7.10 to 7.11, 7.30, 7.31, 7...
High
Unreviewed
CVE-2019-0283
was published
May 13, 2022
SAML authentication vulnerability due to stdlib XML parsing
High
CVE-2020-26276
was published
for
github.com/fleetdm/fleet/v4
(Go)
Feb 11, 2022
Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2...
High
Unreviewed
CVE-2018-12331
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API