GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
57 advisories
Filter by severity
A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the...
Moderate
Unreviewed
CVE-2021-4148
was published
Mar 24, 2022
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration...
Critical
Unreviewed
CVE-2022-29898
was published
May 12, 2022
An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third...
High
Unreviewed
CVE-2018-6336
was published
May 13, 2022
One Identity Cloud Access Manager before 8.1.4 Hotfix 1 allows OTP bypass via vectors involving a...
High
Unreviewed
CVE-2019-13496
was published
May 24, 2022
The update functionality of the Discover Media infotainment system in Volkswagen Polo 2019...
High
Unreviewed
CVE-2020-28656
was published
May 24, 2022
Proofpoint Enterprise Protection (PPS/PoD) before 8.17.0 contains a vulnerability that could...
Moderate
Unreviewed
CVE-2020-14009
was published
May 24, 2022
An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi...
Moderate
Unreviewed
CVE-2020-26141
was published
May 24, 2022
In JetBrains TeamCity before 2020.2.3, insufficient checks of the redirect_uri were made during...
High
Unreviewed
CVE-2021-31913
was published
May 24, 2022
The vulnerability allows a successful attacker to bypass the integrity check of FW uploaded to...
Moderate
Unreviewed
CVE-2021-22276
was published
May 24, 2022
A vulnerability has been identified in SCALANCE XM408-4C (All versions < V6.5), SCALANCE XM408-4C...
High
Unreviewed
CVE-2021-37182
was published
Jun 15, 2022
Honeywell Experion PKS Safety Manager 5.02 has Insufficient Verification of Data Authenticity....
Moderate
Unreviewed
CVE-2022-30316
was published
Jul 29, 2022
An issue was discovered in Qualys Cloud Agent 4.8.0-49. It executes programs at various full...
High
Unreviewed
CVE-2022-29549
was published
Aug 19, 2022
An exploitable firmware modification vulnerability was discovered on the Netgear WPN824EXT WiFi...
High
Unreviewed
CVE-2022-38955
was published
Sep 21, 2022
An exploitable firmware downgrade vulnerability was discovered on the Netgear WPN824EXT WiFi...
Moderate
Unreviewed
CVE-2022-38956
was published
Sep 21, 2022
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update...
Moderate
Unreviewed
CVE-2023-23120
was published
Feb 2, 2023
The use of the cyclic redundancy check (CRC) algorithm for integrity check during firmware update...
Moderate
Unreviewed
CVE-2023-23119
was published
Feb 2, 2023
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can...
Moderate
Unreviewed
CVE-2022-45191
was published
Feb 8, 2023
Briar before 1.4.22 allows attackers to spoof other users' messages in a blog, forum, or private...
Moderate
Unreviewed
CVE-2023-33981
was published
May 24, 2023
Improper validation of integrity check vulnerability in Smart Switch PC prior to version 4.3...
Moderate
Unreviewed
CVE-2023-30673
was published
Jul 6, 2023
Issue summary: The AES-SIV cipher implementation contains a bug that causes
it to ignore empty...
Moderate
Unreviewed
CVE-2023-2975
was published
Jul 14, 2023
All firmware versions of the NPort 5000 Series are affected by an improper validation of...
High
Unreviewed
CVE-2023-4929
was published
Oct 3, 2023
Lack of cryptographic integrity check on TETRA air-interface encrypted traffic. Since a stream...
High
Unreviewed
CVE-2022-24404
was published
Oct 19, 2023
An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through...
Moderate
Unreviewed
CVE-2023-28002
was published
Nov 14, 2023
An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an...
Moderate
Unreviewed
CVE-2023-28802
was published
Nov 21, 2023
A missing integrity check in the update system in ProLion CryptoSpike 3.0.15P2 allows attackers...
High
Unreviewed
CVE-2023-36650
was published
Dec 12, 2023
ProTip!
Advisories are also available from the
GraphQL API