GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            539 advisories
        Filter by severity
        
      
      
    
                    
                      An insecure modification vulnerability in the /etc/passwd file was found in the openshift/ansible...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-19350
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification vulnerability in the /etc/passwd file was found in the container...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-19349
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification vulnerability in the /etc/passwd file was found in the operator...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-19352
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification vulnerability in the /etc/passwd file was found in the operator...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-19354
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification vulnerability in the /etc/passwd file was found in the operator...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2019-19353
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-20208
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2020-10695
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-1594
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      An insecure modification flaw in the /etc/passwd file was found in the openjdk-1.8 and openjdk-11...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-20264
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      The authentication mechanism used by poll workers to administer voting using the tested version...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-1746
                      
                      was published
                      Jun 25, 2022 
                    
                  
                    
                      Incorrect Privilege Assignment in GitHub repository hestiacp/hestiacp prior to 1.6.6.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-2626
                      
                      was published
                      Aug 6, 2022 
                    
                  
                    
                      A vulnerability classified as critical was found in SourceCodester Web-Based Student Clearance...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3436
                      
                      was published
                      Oct 10, 2022 
                    
                  
                    
                      A vulnerability has been found in SourceCodester Human Resource Management System 1.0 and...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3458
                      
                      was published
                      Oct 12, 2022 
                    
                  
                    
                      A vulnerability was found in SourceCodester Human Resource Management System 1.0 and classified...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3496
                      
                      was published
                      Oct 14, 2022 
                    
                  
                    
                      A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3549
                      
                      was published
                      Oct 17, 2022 
                    
                  
                    
                      A vulnerability was found in seccome Ehoney. It has been rated as critical. This issue affects...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-3735
                      
                      was published
                      Oct 28, 2022 
                    
                  
                    
                      This issue was addressed by removing additional entitlements. This issue is fixed in tvOS 16.1,...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-42825
                      
                      was published
                      Nov 2, 2022 
                    
                  
                    
                      A vulnerability, which was classified as critical, was found in SourceCodester Event Registration...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4232
                      
                      was published
                      Nov 30, 2022 
                    
                  
                    
                      A vulnerability, which was classified as critical, has been found in FeMiner wms. Affected by...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4272
                      
                      was published
                      Dec 3, 2022 
                    
                  
                    
                      A vulnerability, which was classified as critical, has been found in SourceCodester Human...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4273
                      
                      was published
                      Dec 3, 2022 
                    
                  
                    
                      A vulnerability has been found in Facepay 1.0 and classified as critical. Affected by this...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4281
                      
                      was published
                      Dec 5, 2022 
                    
                  
                    
                      A vulnerability was found in Click Studios Passwordstate and Passwordstate Browser Extension...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-4613
                      
                      was published
                      Dec 19, 2022 
                    
                  
                    
                      text_helpers uses web link to untrusted target with window.opener access
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-36624
                      
                      was published
                        for
                        
                          text_helpers
                        
                        (RubyGems)
                      Dec 22, 2022 
                    
                  
                    
                      A vulnerability in the web-based management interface of ClearPass Policy Manager could allow a...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-25591
                      
                      was published
                      Mar 22, 2023 
                    
                  
                    
                      In onAttach of SettingsPreferenceFragment.java, there is a possible bypass of Factory Reset...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-20957
                      
                      was published
                      Mar 24, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API