GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
229 advisories
Filter by severity
The AMDPowerProfiler.sys driver of AMD ?Prof tool may allow lower privileged users to access MSRs...
Critical
Unreviewed
CVE-2021-26334
was published
Dec 2, 2021
Raspberry Pi OS through 5.10 has the raspberry default password for the pi account. If not...
Critical
Unreviewed
CVE-2021-38759
was published
Dec 8, 2021
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using...
Critical
Unreviewed
CVE-2021-42128
was published
Dec 8, 2021
Product: AndroidVersions: Android kernelAndroid ID: A-192641593References: N/A
Critical
Unreviewed
CVE-2021-39655
was published
Dec 16, 2021
Product: AndroidVersions: Android kernelAndroid ID: A-199805112References: N/A
Critical
Unreviewed
CVE-2021-39645
was published
Dec 16, 2021
Product: AndroidVersions: Android kernelAndroid ID: A-126949257References: N/A
Critical
Unreviewed
CVE-2021-39641
was published
Dec 16, 2021
Product: AndroidVersions: Android kernelAndroid ID: A-199809304References: N/A
Critical
Unreviewed
CVE-2021-39644
was published
Dec 16, 2021
Phone Manager application has a Improper Privilege Management vulnerability.Successful...
Critical
Unreviewed
CVE-2021-39982
was published
Jan 4, 2022
There is a Configuration defects in Smartphone.Successful exploitation of this vulnerability may...
Critical
Unreviewed
CVE-2021-37121
was published
Jan 4, 2022
StarWind SAN & NAS build 1578 and StarWind Command Center Build 6864 Update Manager allows...
Critical
Unreviewed
CVE-2021-45389
was published
Jan 5, 2022
The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation...
Critical
Unreviewed
CVE-2022-22704
was published
Jan 7, 2022
Windows Hyper-V Elevation of Privilege Vulnerability.
Critical
Unreviewed
CVE-2022-21901
was published
Jan 12, 2022
In doRead of SimpleDecodingSource.cpp, there is a possible out of bounds write due to an...
Critical
Unreviewed
CVE-2021-39623
was published
Jan 15, 2022
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an...
Critical
Unreviewed
CVE-2022-22832
was published
Feb 8, 2022
All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege...
Critical
Unreviewed
CVE-2021-36302
was published
Feb 10, 2022
An incorrect check in the component cdr.php of Voipmonitor GUI before v24.96 allows...
Critical
Unreviewed
CVE-2022-24259
was published
Feb 10, 2022
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30...
Critical
Unreviewed
CVE-2022-24927
was published
Feb 12, 2022
A CWE-269: Improper Privilege Management vulnerability exists that could cause an arbitrary...
Critical
Unreviewed
CVE-2021-22801
was published
Feb 12, 2022
XCOM Data Transport for Windows, Linux, and UNIX 11.6 releases contain a vulnerability due to...
Critical
Unreviewed
CVE-2022-23992
was published
Feb 15, 2022
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when...
Critical
Unreviewed
CVE-2022-25643
was published
Feb 25, 2022
PCManager versions 11.1.1.95 has a privilege escalation vulnerability. Successful exploit could...
Critical
Unreviewed
CVE-2021-40046
was published
Feb 26, 2022
Zoho ManageEngine SharePoint Manager Plus before 4329 is vulnerable to a sensitive data leak that...
Critical
Unreviewed
CVE-2022-24305
was published
Mar 3, 2022
Printix Secure Cloud Print Management 1.3.1035.0 incorrectly uses Privileged APIs.
Critical
Unreviewed
CVE-2022-25089
was published
Mar 4, 2022
The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when...
Critical
Unreviewed
CVE-2022-0441
was published
Mar 8, 2022
The System Diagnosis service of MyASUS before 3.1.2.0 allows privilege escalation.
Critical
Unreviewed
CVE-2022-22814
was published
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API