GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
183 advisories
Filter by severity
Insufficient data validation in UI in Google Chrome prior to 87.0.4280.66 allowed a remote...
Moderate
Unreviewed
CVE-2020-16031
was published
May 24, 2022
Insufficient data validation in sharing in Google Chrome prior to 87.0.4280.66 allowed a remote...
Moderate
Unreviewed
CVE-2020-16032
was published
May 24, 2022
IBM Spectrum Protect Plus 10.1.0 through 10.1.6 could allow a remote attacker to hijack the...
Moderate
Unreviewed
CVE-2020-5020
was published
May 24, 2022
IBM Jazz Foundation products could allow a remote attacker to hijack the clicking action of the...
Moderate
Unreviewed
CVE-2020-4547
was published
May 24, 2022
Inappropriate implementation in iframe sandbox in Google Chrome prior to 88.0.4324.96 allowed a...
Moderate
Unreviewed
CVE-2021-21139
was published
May 24, 2022
SAP Business Objects BI Platform, versions - 410, 420, 430, allows multiple X-Frame-Options...
Moderate
Unreviewed
CVE-2021-21444
was published
May 24, 2022
The browser could have been confused into transferring a pointer lock state into another tab,...
Moderate
Unreviewed
CVE-2021-23955
was published
May 24, 2022
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in...
Moderate
Unreviewed
CVE-2020-10743
was published
May 24, 2022
In onStart of ContactsDumpActivity.java, there is possible access to contacts due to a tapjacking...
Moderate
Unreviewed
CVE-2021-0569
was published
May 24, 2022
Text injection/Content Spoofing in 404 page in Zammad 1.0.x up to 4.0.0 could allow remote...
Moderate
Unreviewed
CVE-2021-35300
was published
May 24, 2022
IBM Sterling Connect:Direct Browser User Interface 1.4.1.1 and 1.5.0.2 could allow a remote...
Moderate
Unreviewed
CVE-2021-20560
was published
May 24, 2022
Showing the legitimate URL in the address bar while loading the content from other domain. This...
Moderate
Unreviewed
CVE-2021-33596
was published
May 24, 2022
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2021-37788
was published
May 24, 2022
The MiCollab Client Service component in Mitel MiCollab before 9.3 could allow an attacker to...
Moderate
Unreviewed
CVE-2021-32070
was published
May 24, 2022
LedgerSMB does not sufficiently guard against being wrapped by other sites, making it vulnerable...
Moderate
Unreviewed
CVE-2021-3731
was published
May 24, 2022
A vulnerability involving insufficient HTTP security headers has been reported to affect QNAP NAS...
Moderate
Unreviewed
CVE-2018-19957
was published
May 24, 2022
grav-plugin-admin is vulnerable to Improper Restriction of Rendered UI Layers or Frames
Moderate
Unreviewed
CVE-2021-3799
was published
May 24, 2022
Incorrect security UI in Web Browser UI in Google Chrome prior to 94.0.4606.54 allowed a remote...
Moderate
Unreviewed
CVE-2021-37971
was published
May 24, 2022
Clustered Data ONTAP versions prior to 9.5P18, 9.6P15, 9.7P14, 9.8P5 and 9.9.1 are missing an X...
Moderate
Unreviewed
CVE-2021-27003
was published
May 24, 2022
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to...
Moderate
Unreviewed
CVE-2021-35237
was published
May 24, 2022
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer....
Moderate
Unreviewed
CVE-2021-27467
was published
May 24, 2022
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 management portal does not...
Moderate
Unreviewed
CVE-2021-38472
was published
May 24, 2022
A vulnerability was found in Ucweb UC Browser 11.2.5.932. It has been classified as critical....
Moderate
Unreviewed
CVE-2017-20041
was published
Jun 14, 2022
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2)....
Moderate
Unreviewed
CVE-2022-27220
was published
Jun 15, 2022
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2)....
Moderate
Unreviewed
CVE-2022-27219
was published
Jun 15, 2022
ProTip!
Advisories are also available from the
GraphQL API