GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,133
Erlang
29
GitHub Actions
19
Go
1,939
Maven
5,000+
npm
3,677
NuGet
643
pip
3,295
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
159 advisories
Filter by severity
The Jeg Elementor Kit plugin for WordPress is vulnerable to authorization bypass in various...
High
Unreviewed
CVE-2022-3805
was published
Dec 22, 2022
Improper Access Control in GitHub repository openemr/openemr prior to 7.0.0.2.
High
Unreviewed
CVE-2022-4505
was published
Dec 15, 2022
The Workreap WordPress theme before 2.6.3 has a vulnerability with the notifications feature as...
High
Unreviewed
CVE-2022-3846
was published
Dec 5, 2022
An Insecure Direct Object Reference (IDOR) vulnerability in the password reset function of Telos...
High
Unreviewed
CVE-2022-43326
was published
Nov 29, 2022
The user_id and device_id on the Ourphoto App version 1.4.1 /device/* end-points both suffer from...
High
Unreviewed
CVE-2022-24187
was published
Nov 29, 2022
An API Endpoint used by Miele's "AppWash" MobileApp in all versions was vulnerable to an...
High
Unreviewed
CVE-2022-3589
was published
Nov 21, 2022
The function check_is_login_page() uses headers for the IP check, which can be easily spoofed.
High
Unreviewed
CVE-2022-1579
was published
Nov 21, 2022
Multiple Insecure Direct Object References (IDOR) vulnerabilities in ExpressTech Quiz And Survey...
High
Unreviewed
CVE-2021-36906
was published
Nov 4, 2022
An access control issue in nopcommerce v4.50.2 allows attackers to arbitrarily modify any...
High
Unreviewed
CVE-2022-33077
was published
Oct 19, 2022
The DevExpress Resource Handler (ASPxHttpHandlerModule) in DevExpress ASP.NET Web Forms Build v19...
High
Unreviewed
CVE-2022-41479
was published
Oct 18, 2022
WeDayCare B.V Ouderapp before v1.1.22 allows attackers to alter the ID value within intercepted...
High
Unreviewed
CVE-2022-36539
was published
Sep 8, 2022
The forgot password token basically just makes us capable of taking over the account of whoever...
High
Unreviewed
CVE-2022-3019
was published
Aug 29, 2022
The WSM Downloader WordPress plugin through 1.4.0 allows only specific popular websites to...
High
Unreviewed
CVE-2022-2367
was published
Aug 9, 2022
Insecure Direct Object Reference vulnerability in HYPR Server before version 6.14.1 allows remote...
High
Unreviewed
CVE-2022-2193
was published
Jul 20, 2022
The WP User Manager WordPress plugin before 2.6.3 does not ensure that the user ID to reset the...
High
Unreviewed
CVE-2021-24655
was published
Jul 18, 2022
The WP-EMail WordPress plugin before 2.69.0 prioritizes getting a visitor's IP from certain HTTP...
High
Unreviewed
CVE-2022-1614
was published
Jun 21, 2022
An issue in the delete_post() function of Online Discussion Forum Site 1 allows unauthenticated...
High
Unreviewed
CVE-2022-31295
was published
Jun 17, 2022
The iQ Block Country WordPress plugin through 1.2.13 does not properly checks HTTP headers in...
High
Unreviewed
CVE-2022-1762
was published
Jun 14, 2022
The LMS by LifterLMS – Online Course, Membership & Learning Management System Plugin for...
High
Unreviewed
CVE-2021-24562
was published
May 24, 2022
Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9...
High
Unreviewed
CVE-2021-24892
was published
May 24, 2022
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to...
High
Unreviewed
CVE-2021-41305
was published
May 24, 2022
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to...
High
Unreviewed
CVE-2021-41306
was published
May 24, 2022
Affected versions of Atlassian Jira Server and Data Center allow unauthenticated remote attackers...
High
Unreviewed
CVE-2021-41307
was published
May 24, 2022
Authorization bypass through user-controlled key vulnerability in MELSEC iQ-R series Safety CPU...
High
Unreviewed
CVE-2021-20599
was published
May 24, 2022
In Yellowfin before 9.6.1 it is possible to enumerate and download users profile pictures through...
High
Unreviewed
CVE-2021-36388
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API