GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
491 advisories
Filter by severity
In multiple managed switches by WAGO in different versions without authorization and with...
Critical
Unreviewed
CVE-2021-20998
was published
May 24, 2022
IBM Security Identity Governance and Intelligence 5.2.6 does not perform any authentication for...
Critical
Unreviewed
CVE-2020-4958
was published
May 24, 2022
themegrill-demo-importer before 1.6.2 does not require authentication for wiping the database,...
Critical
Unreviewed
CVE-2020-36333
was published
May 24, 2022
An issue was discovered in SquareBox CatDV Server through 9.2. An attacker can invoke sensitive...
Critical
Unreviewed
CVE-2021-26705
was published
May 24, 2022
The official kong docker images before 1.0.2-alpine (Alpine specific) contain a blank password...
Critical
Unreviewed
CVE-2020-35189
was published
May 24, 2022
The official vault docker images before 0.11.6 contain a blank password for a root user. System...
Critical
Unreviewed
CVE-2020-35192
was published
May 24, 2022
The official plone Docker images before version of 4.3.18-alpine (Alpine specific) contain a...
Critical
Unreviewed
CVE-2020-35190
was published
May 24, 2022
The official memcached docker images before 1.5.11-alpine (Alpine specific) contain a blank...
Critical
Unreviewed
CVE-2020-35197
was published
May 24, 2022
The official haproxy docker images before 1.8.18-alpine (Alpine specific) contain a blank...
Critical
Unreviewed
CVE-2020-35195
was published
May 24, 2022
Access to the Advantech iView versions prior to v5.7.03.6112 configuration are missing...
Critical
Unreviewed
CVE-2021-22652
was published
May 24, 2022
The default configuration of Crimson 3.1 (Build versions prior to 3119.001) allows a user to be...
Critical
Unreviewed
CVE-2020-27285
was published
May 24, 2022
An issue was discovered in URVE Build 24.03.2020. Using the _internal/pc/shutdown.php path, it is...
Critical
Unreviewed
CVE-2020-29551
was published
May 24, 2022
The FullArmor HAPI File Share Mount Docker image through 2020-12-14 contains a blank password for...
Critical
Unreviewed
CVE-2020-35465
was published
May 24, 2022
Version 3.16.0 of the CoScale agent Docker image contains a blank password for the root user....
Critical
Unreviewed
CVE-2020-35462
was published
May 24, 2022
Version 1.3.0 of the Weave Cloud Agent Docker image contains a blank password for the root user....
Critical
Unreviewed
CVE-2020-35464
was published
May 24, 2022
The Software AG Terracotta Server OSS Docker image 5.4.1 contains a blank password for the root...
Critical
Unreviewed
CVE-2020-35469
was published
May 24, 2022
The official chronograf docker images before 1.7.7-alpine (Alpine specific) contain a blank...
Critical
Unreviewed
CVE-2020-35188
was published
May 24, 2022
The official ghost docker images before 2.16.1-alpine (Alpine specific) contain a blank password...
Critical
Unreviewed
CVE-2020-35185
was published
May 24, 2022
The official adminer docker images before 4.7.0-fastcgi contain a blank password for a root user....
Critical
Unreviewed
CVE-2020-35186
was published
May 24, 2022
The Docker Docs Docker image through 2020-12-14 contains a blank password for the root user....
Critical
Unreviewed
CVE-2020-35467
was published
May 24, 2022
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3)....
Critical
Unreviewed
CVE-2020-25228
was published
May 24, 2022
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the Web Server on...
Critical
Unreviewed
CVE-2020-7540
was published
May 24, 2022
The official Crux Linux Docker images 3.0 through 3.4 contain a blank password for a root user....
Critical
Unreviewed
CVE-2020-29389
was published
May 24, 2022
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an...
Critical
Unreviewed
CVE-2020-3531
was published
May 24, 2022
The official influxdb docker images before 1.7.3-meta-alpine (Alpine specific) contain a blank...
Critical
Unreviewed
CVE-2020-35194
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API