GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,762
NuGet
678
pip
3,447
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
244 advisories
Filter by severity
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking...
Moderate
Unreviewed
CVE-2023-6206
was published
Nov 21, 2023
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque...
Moderate
Unreviewed
CVE-2023-4956
was published
Nov 7, 2023
It was possible for certain browser prompts and dialogs to be activated or dismissed...
Moderate
Unreviewed
CVE-2023-5721
was published
Oct 25, 2023
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10,...
Moderate
Unreviewed
CVE-2023-36920
was published
Oct 30, 2023
Economizzer vulnerable to Clickjacking
Moderate
CVE-2023-38873
was published
for
gugoan/economizzer
(Composer)
Sep 28, 2023
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2021-37788
was published
May 24, 2022
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to...
Moderate
Unreviewed
CVE-2021-35237
was published
May 24, 2022
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote...
Moderate
Unreviewed
CVE-2022-20852
was published
Aug 11, 2022
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16,...
Moderate
Unreviewed
CVE-2022-32891
was published
Feb 27, 2023
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS...
Moderate
Unreviewed
CVE-2022-42799
was published
Nov 2, 2022
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management ...
Moderate
Unreviewed
CVE-2021-27414
was published
Mar 12, 2022
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP...
Moderate
Unreviewed
CVE-2019-19001
was published
May 24, 2022
Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior...
Moderate
Unreviewed
CVE-2023-1362
was published
Mar 13, 2023
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
Moderate
Unreviewed
CVE-2020-10951
was published
May 24, 2022
Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit
Moderate
CVE-2023-0780
was published
for
cockpit-hq/cockpit
(Composer)
Feb 11, 2023
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and...
Moderate
Unreviewed
CVE-2023-23126
was published
Feb 1, 2023
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An...
Moderate
Unreviewed
CVE-2022-45096
was published
Feb 1, 2023
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in...
Moderate
Unreviewed
CVE-2020-10743
was published
May 24, 2022
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to...
High
Unreviewed
CVE-2023-20913
was published
Jan 26, 2023
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to...
Moderate
Unreviewed
CVE-2021-3660
was published
Mar 11, 2022
Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2022-40268
was published
Feb 2, 2023
In onCreate of MasterClearConfirmFragment.java, there is a possible factory reset due to a...
Moderate
Unreviewed
CVE-2022-20215
was published
Jan 26, 2023
In Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking...
Moderate
Unreviewed
CVE-2022-20214
was published
Jan 26, 2023
IBM BigFix Platform 9.2 and 9.5 could allow a low-privilege user to manipulate the UI into...
Moderate
Unreviewed
CVE-2019-4058
was published
May 24, 2022
IBM WebSphere Application Server 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3...
Moderate
Unreviewed
CVE-2021-39038
was published
Feb 25, 2022
ProTip!
Advisories are also available from the
GraphQL API