GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
241 advisories
Filter by severity
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management ...
Moderate
Unreviewed
CVE-2021-27414
was published
Mar 12, 2022
Spoofing attack in swagger-ui-dist
Moderate
CVE-2021-46708
was published
for
swagger-ui-dist
(npm)
Mar 12, 2022
Improper Restriction of Rendered UI Layers or Frames in Sylius
Moderate
CVE-2022-24733
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile...
High
Unreviewed
CVE-2021-39692
was published
Mar 17, 2022
In onCreate of RequestManageCredentials.java, there is a possible way for a third party app to...
High
Unreviewed
CVE-2021-39702
was published
Mar 17, 2022
The DuckDuckGo browser 7.64.4 on iOS allows Address Bar Spoofing due to mishandling of the...
High
Unreviewed
CVE-2021-44683
was published
Mar 27, 2022
In JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party...
Moderate
Unreviewed
CVE-2022-28649
was published
Apr 6, 2022
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick...
High
Unreviewed
CVE-2021-39796
was published
Apr 13, 2022
A design error in Opera 8.01 and earlier allows user-assisted attackers to execute arbitrary code...
Moderate
Unreviewed
CVE-2005-2407
was published
May 1, 2022
Unspecified vulnerability in Opera before 9.5 allows remote attackers to spoof the contents of...
Moderate
Unreviewed
CVE-2008-2716
was published
May 1, 2022
This vulnerability allows users to execute a clickjacking attack in the meeting's chat.
Moderate
Unreviewed
CVE-2021-27773
was published
May 13, 2022
Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content...
Moderate
Unreviewed
CVE-2011-1244
was published
May 13, 2022
IBM Tivoli Storage Manager (IBM Spectrum Protect 7.1 and 8.1) could allow a remote attacker to...
Moderate
Unreviewed
CVE-2018-1853
was published
May 13, 2022
Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to bypass the Same...
Moderate
Unreviewed
CVE-2014-1483
was published
May 13, 2022
A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote...
Moderate
Unreviewed
CVE-2018-15423
was published
May 13, 2022
A vulnerability in the web UI of Cisco Unified Communications Manager (Unified CM) could allow an...
Moderate
Unreviewed
CVE-2018-0355
was published
May 13, 2022
Improper countermeasure against clickjacking attack in client certificates management screen was...
Moderate
Unreviewed
CVE-2018-16172
was published
May 13, 2022
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 could allow...
Moderate
Unreviewed
CVE-2018-1803
was published
May 13, 2022
When the RSS Feed preview about:feeds page is framed within another page, it can be used in...
High
Unreviewed
CVE-2018-18496
was published
May 13, 2022
Eliding from the wrong side in an infobar in DevTools in Google Chrome prior to 68.0.3440.75...
Moderate
Unreviewed
CVE-2018-6178
was published
May 13, 2022
A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and...
Moderate
Unreviewed
CVE-2018-6909
was published
May 13, 2022
In PrestaShop through 1.7.2.5, a UI-Redressing/Clickjacking vulnerability was found that might...
High
Unreviewed
CVE-2018-7491
was published
May 13, 2022
Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0...
Moderate
Unreviewed
CVE-2019-5767
was published
May 13, 2022
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox...
Moderate
Unreviewed
CVE-2013-5614
was published
May 13, 2022
The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does...
Moderate
Unreviewed
CVE-2014-1480
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API