GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
162 advisories
Filter by severity
Tomcat application credentials are hardcoded in SonicWall GMS and Analytics configuration file....
Critical
Unreviewed
CVE-2023-34128
was published
Jul 13, 2023
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security...
Critical
Unreviewed
CVE-2022-4693
was published
Jul 6, 2023
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all...
Critical
Unreviewed
CVE-2023-26204
was published
Jun 13, 2023
This vulnerability exists in GajShield Data Security Firewall firmware versions prior to v4.28 ...
Critical
Unreviewed
CVE-2023-1778
was published
Apr 27, 2023
A vulnerability in the expo.io framework allows an attacker to take over accounts and steal...
Critical
Unreviewed
CVE-2023-28131
was published
Apr 24, 2023
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file...
Critical
Unreviewed
CVE-2022-45599
was published
Feb 23, 2023
Ricoh mp_c4504ex devices with firmware 1.06 mishandle credentials.
Critical
Unreviewed
CVE-2022-43969
was published
Feb 16, 2023
COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1...
Critical
Unreviewed
CVE-2022-47697
was published
Jan 31, 2023
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in...
Critical
Unreviewed
CVE-2022-32519
was published
Jan 31, 2023
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in...
Critical
Unreviewed
CVE-2022-32518
was published
Jan 31, 2023
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in...
Critical
Unreviewed
CVE-2022-32520
was published
Jan 31, 2023
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to...
Critical
Unreviewed
CVE-2022-46967
was published
Jan 27, 2023
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated...
Critical
Unreviewed
CVE-2022-45276
was published
Nov 23, 2022
patrickfuller camp up to and including commit bbd53a256ed70e79bd8758080936afbf6d738767 is...
Critical
Unreviewed
CVE-2022-37109
was published
Nov 15, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has the q6xV4aW8bQ4cfD-b password for the axiros account.
Critical
Unreviewed
CVE-2020-15347
was published
Sep 30, 2022
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may...
Critical
Unreviewed
CVE-2022-30601
was published
Aug 19, 2022
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible...
Critical
Unreviewed
CVE-2022-30285
was published
Aug 3, 2022
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force...
Critical
Unreviewed
CVE-2021-22640
was published
Jul 29, 2022
Xiaongmai AHB7008T-MH-V2, AHB7804R-ELS, AHB7804R-MH-V2, AHB7808R-MS-V2, AHB7808R-MS, AHB7808T-MS...
Critical
Unreviewed
CVE-2021-41506
was published
Jul 1, 2022
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker...
Critical
Unreviewed
CVE-2022-31887
was published
Jun 29, 2022
An attacker with weak credentials could access the TCP port via an open FTP port, allowing an...
Critical
Unreviewed
CVE-2022-2103
was published
Jun 25, 2022
The Orca HCM digital learning platform uses a weak factory default administrator password, which...
Critical
Unreviewed
CVE-2021-35965
was published
May 24, 2022
In SapphireIMS 5.0, it is possible to take over an account by sending a request to the...
Critical
Unreviewed
CVE-2020-25566
was published
May 24, 2022
The manage users profile services of the network camera device allows an authenticated. Remote...
Critical
Unreviewed
CVE-2021-30167
was published
May 24, 2022
The Vangene deltaFlow E-platform does not take properly protective measures. Attackers can obtain...
Critical
Unreviewed
CVE-2021-28171
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API