GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,782
Erlang
36
GitHub Actions
29
Go
2,347
Maven
5,000+
npm
3,976
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,670 advisories
Filter by severity
Improper access control allows admin privilege escalation in Argo CD
Critical
CVE-2022-24768
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 24, 2022
It was found that 3scale's APIdocs does not validate the access token, in the case of invalid...
High
Unreviewed
CVE-2021-3814
was published
Mar 26, 2022
Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz...
Moderate
Unreviewed
CVE-2022-27948
was published
Mar 28, 2022
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access...
High
Unreviewed
CVE-2022-27658
was published
Mar 29, 2022
The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of...
Moderate
Unreviewed
CVE-2022-0833
was published
Mar 29, 2022
The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related...
Moderate
Unreviewed
CVE-2021-24978
was published
Mar 29, 2022
Missing permission Jenkins Pipeline Phoenix AutoTest Plugin
Moderate
CVE-2022-28158
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
Missing permission check in Jenkins Continuous Integration with Toad Edge Plugin
Moderate
CVE-2022-28147
was published
for
org.jenkins-ci.plugins:ci-with-toad-edge
(Maven)
Mar 30, 2022
Missing permission check in Jenkins Job and Node ownership Plugin
Moderate
CVE-2022-28151
was published
for
com.synopsys.jenkinsci:ownership
(Maven)
Mar 30, 2022
Missing permission checks in Jenkins Proxmox Plugin
Moderate
CVE-2022-28144
was published
for
org.jenkins-ci.plugins:proxmox
(Maven)
Mar 30, 2022
Missing permission check in Jenkins RocketChat Notifier Plugin
Moderate
CVE-2022-28139
was published
for
org.jenkins-ci.plugins:rocketchatnotifier
(Maven)
Mar 30, 2022
Missing permission check in Jenkins JiraTestResultReporter Plugin
Moderate
CVE-2022-28137
was published
for
org.jenkins-ci.plugins:JiraTestResultReporter
(Maven)
Mar 30, 2022
Missing permission checks in Jekins Bitbucket Server Integration Plugin
Moderate
CVE-2022-28134
was published
for
io.jenkins.plugins:atlassian-bitbucket-server-integration
(Maven)
Mar 30, 2022
In Settings, there is a possible way to add an auto-connect WiFi network without the user's...
High
Unreviewed
CVE-2021-39768
was published
Mar 31, 2022
In WindowManager, there is a possible way to start a foreground activity from the background due...
High
Unreviewed
CVE-2021-39758
was published
Mar 31, 2022
Hospital Management System v1.0 was discovered to lack an authorization component, allowing...
Critical
Unreviewed
CVE-2022-26546
was published
Apr 1, 2022
Missing authorization vulnerability in Advanced Custom Fields versions prior to 5.12.1 and...
Moderate
Unreviewed
CVE-2022-23183
was published
Apr 1, 2022
The Amelia WordPress plugin before 1.0.48 does not have proper authorisation when handling Amelia...
Moderate
Unreviewed
CVE-2022-0837
was published
Apr 5, 2022
The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing...
Moderate
Unreviewed
CVE-2022-0825
was published
Apr 5, 2022
The Material Design for Contact Form 7 WordPress plugin through 2.6.4 does not check...
Moderate
Unreviewed
CVE-2022-0404
was published
Apr 5, 2022
An intent redirection issue was doscovered in Sina Weibo Android SDK 4.2.7 (com.sina.weibo.sdk...
High
Unreviewed
CVE-2020-23349
was published
Apr 6, 2022
The Salon booking system Free and pro WordPress plugins before 7.6.3 do not have proper...
Moderate
Unreviewed
CVE-2022-0919
was published
Apr 12, 2022
Missing permission checks in Jenkins Publish Over FTP Plugin
Moderate
CVE-2022-29051
was published
for
org.jenkins-ci.plugins:publish-over-ftp
(Maven)
Apr 13, 2022
An unauthenticated user can use functions of XML Data Archiving Service of SAP NetWeaver...
High
Unreviewed
CVE-2022-27669
was published
Apr 13, 2022
A vulnerability has been identified in SICAM A8000 CP-8031 (All versions < V4.80), SICAM A8000 CP...
High
Unreviewed
CVE-2022-27480
was published
Apr 13, 2022
ProTip!
Advisories are also available from the
GraphQL API