GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,969 advisories
Filter by severity
The Ultimate Product Catalog WordPress plugin before 5.0.26 does not have authorisation and CSRF...
Moderate
Unreviewed
CVE-2021-24993
was published
Feb 8, 2022
The Advanced Cron Manager WordPress plugin before 2.4.2, advanced-cron-manager-pro WordPress...
Moderate
Unreviewed
CVE-2021-25084
was published
Feb 8, 2022
The SupportCandy WordPress plugin before 2.2.5 does not have authorisation and CRSF checks in its...
Moderate
Unreviewed
CVE-2021-24839
was published
Feb 8, 2022
Missing authorization in xwiki-platform
Moderate
CVE-2022-23617
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Feb 9, 2022
Missing authorization in xwiki-platform
Moderate
CVE-2022-23621
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Feb 9, 2022
Improper Access Control in infinispan-server-runtime
Moderate
CVE-2020-25711
was published
for
org.infinispan:infinispan-core
(Maven)
Feb 9, 2022
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks...
Moderate
Unreviewed
CVE-2022-22535
was published
Feb 11, 2022
Improper Privilege Management in Snipe-IT
Moderate
CVE-2022-0579
was published
for
snipe/snipe-it
(Composer)
Feb 15, 2022
The CMP WordPress plugin before 4.0.19 allows any user, even not logged in, may arbitrarily...
Moderate
Unreviewed
CVE-2022-0188
was published
Feb 15, 2022
The PPOM for WooCommerce WordPress plugin before 24.0 does not have authorisation and CSRF checks...
Moderate
Unreviewed
CVE-2021-25018
was published
Feb 15, 2022
Missing Authorization in Harbor
Moderate
CVE-2019-16097
was published
for
github.com/goharbor/harbor
(Go)
Feb 15, 2022
Missing permission check in Jenkins SWAMP Plugin allows capturing credentials
Moderate
CVE-2022-25211
was published
for
org.continuousassurance.swamp.jenkins:swamp
(Maven)
Feb 16, 2022
Missing permission checks in Jenkins Checkmarx Plugin allow capturing credentials
Moderate
CVE-2022-25201
was published
for
com.checkmarx.jenkins:checkmarx
(Maven)
Feb 16, 2022
Missing permission check in Jenkins autonomiq Plugin
Moderate
CVE-2022-25195
was published
for
io.jenkins.plugins:autonomiq
(Maven)
Feb 16, 2022
Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization
Moderate
CVE-2022-25193
was published
for
io.jenkins.plugins:embotics-vcommander
(Maven)
Feb 16, 2022
Missing permission check in Jenkins Conjur Secrets Plugin allows enumerating credentials IDs
Moderate
CVE-2022-25190
was published
for
org.conjur.jenkins:conjur-credentials
(Maven)
Feb 16, 2022
Exposure of Sensitive Information to an Unauthorized Actor in librenms
Moderate
CVE-2022-0588
was published
for
librenms/librenms
(Composer)
Feb 16, 2022
PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events...
Moderate
Unreviewed
CVE-2021-46701
was published
Feb 21, 2022
Improper Authorization in GitHub repository chocobozzz/peertube prior to 4.1.0.
Moderate
Unreviewed
CVE-2022-0726
was published
Feb 24, 2022
EC-CUBE improperly handles HTTP Host header values
Moderate
CVE-2022-25355
was published
for
ec-cube/ec-cube
(Composer)
Feb 25, 2022
In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address.
Moderate
Unreviewed
CVE-2022-24594
was published
Feb 26, 2022
The Customize WordPress Emails and Alerts WordPress plugin before 1.8.7 does not have...
Moderate
Unreviewed
CVE-2022-0345
was published
Mar 1, 2022
The Maps Plugin using Google Maps for WordPress plugin before 1.8.1 does not have proper...
Moderate
Unreviewed
CVE-2021-25011
was published
Mar 1, 2022
The Use Any Font | Custom Font Uploader WordPress plugin before 6.2.1 does not have any...
Moderate
Unreviewed
CVE-2021-24977
was published
Mar 1, 2022
ProTip!
Advisories are also available from the
GraphQL API