GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,828
Maven
5,000+
npm
5,000+
NuGet
942
pip
5,000+
Pub
13
RubyGems
1,060
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1...
Critical
Unreviewed
CVE-2018-20512
was published
May 13, 2022
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0,...
Moderate
Unreviewed
CVE-2017-8034
was published
May 13, 2022
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to...
Critical
Unreviewed
CVE-2017-7279
was published
May 13, 2022
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an...
High
Unreviewed
CVE-2017-6896
was published
May 13, 2022
Google Chrome before 15.0.874.102 does not properly handle javascript: URLs, which allows remote...
Moderate
Unreviewed
CVE-2011-3887
was published
May 13, 2022
An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and...
High
Unreviewed
CVE-2018-19224
was published
May 13, 2022
An issue in upload.csp of FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows attackers to write...
High
Unreviewed
CVE-2022-28113
was published
Apr 16, 2022
WAGO 750-8212 PFC200 G2 2ETH RS Firmware version 03.05.10(17) is affected by a privilege...
High
Unreviewed
CVE-2021-46388
was published
Feb 17, 2022
Unisphere for PowerMax versions prior to 9.2.2.2 contains a privilege escalation vulnerability....
High
Unreviewed
CVE-2021-36338
was published
Jan 22, 2022
Cookie Prefix Spoofing in CGI::Cookie.parse
High
CVE-2021-41819
was published
for
cgi
(RubyGems)
Jan 21, 2022
Rails Multisite secure/signed cookies share secrets between sites in a multi-site application
Moderate
CVE-2021-41263
was published
for
rails_multisite
(RubyGems)
Nov 15, 2021
Reliance on Cookies without Validation and Integrity Checking in getgrav/grav
Moderate
CVE-2021-3818
was published
for
getgrav/grav
(Composer)
Sep 29, 2021
Lack of protection against cookie tossing attacks in fastify-csrf
Moderate
CVE-2021-29624
was published
for
fastify-csrf
(npm)
May 17, 2021
Reliance on Cookies without validation in OctoberCMS
Moderate
CVE-2020-15128
was published
for
october/rain
(Composer)
Aug 5, 2020
ProTip!
Advisories are also available from the
GraphQL API