GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            5,284 advisories
        Filter by severity
        
      
      
    
                    
                      Missing permission check in Jenkins Job and Node ownership Plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-28151
                      
                      was published
                        for
                        
                          com.synopsys.jenkinsci:ownership
                        
                        (Maven)
                      Mar 30, 2022 
                    
                  
                    
                      Missing permission check in Jenkins Continuous Integration with Toad Edge Plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-28147
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:ci-with-toad-edge
                        
                        (Maven)
                      Mar 30, 2022 
                    
                  
                    
                      Missing permission Jenkins Pipeline Phoenix AutoTest Plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-28158
                      
                      was published
                        for
                        
                          com.surenpi.jenkins:phoenix-autotest
                        
                        (Maven)
                      Mar 30, 2022 
                    
                  
                    
                      The OSMapper WordPress plugin through 2.1.5 contains an AJAX action to delete a plugin related...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-24978
                      
                      was published
                      Mar 29, 2022 
                    
                  
                    
                      The Church Admin WordPress plugin before 3.4.135 does not have authorisation and CSRF in some of...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0833
                      
                      was published
                      Mar 29, 2022 
                    
                  
                    
                      Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-27658
                      
                      was published
                      Mar 29, 2022 
                    
                  
                    
                      Certain Tesla vehicles through 2022-03-26 allow attackers to open the charging port via a 315 MHz...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-27948
                      
                      was published
                      Mar 28, 2022 
                    
                  
                    
                      It was found that 3scale's APIdocs does not validate the access token, in the case of invalid...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-3814
                      
                      was published
                      Mar 26, 2022 
                    
                  
                    
                      Improper access control allows admin privilege escalation in Argo CD
                    
                      
  Critical
                    
                
                      
                        CVE-2022-24768
                      
                      was published
                        for
                        
                          github.com/argoproj/argo-cd
                        
                        (Go)
                      Mar 24, 2022 
                    
                  
                    
                      idcCMS v1.10 was discovered to contain an issue which allows attackers to arbitrarily delete the...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-27333
                      
                      was published
                      Mar 23, 2022 
                    
                  
                    
                      Renderers can obtain access to random bluetooth device without permission in Electron
                    
                      
  Low
                    
                
                      
                        CVE-2022-21718
                      
                      was published
                        for
                        
                          electron
                        
                        (npm)
                      Mar 22, 2022 
                    
                  
                    
                      Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-45878
                      
                      was published
                      Mar 22, 2022 
                    
                  
                    
                      The miniOrange's Google Authenticator WordPress plugin before 5.5 does not have proper...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-0229
                      
                      was published
                      Mar 22, 2022 
                    
                  
                    
                      Automotive Grade Linux Kooky Koi 11.0.0, 11.0.1, 11.0.2, 11.0.3, 11.0.4, and 11.0.5 is affected...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-24595
                      
                      was published
                      Mar 19, 2022 
                    
                  
                    
                      An issue was discovered in Projectworlds Hospital Management System v1.0. Unauthorized malicious...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-45852
                      
                      was published
                      Mar 17, 2022 
                    
                  
                    
                      Missing permission checks in AWS Credentials Plugin 
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-27199
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:aws-credentials
                        
                        (Maven)
                      Mar 16, 2022 
                    
                  
                    
                      CSRF vulnerability and missing permission checks in Extended Choice Parameter Plugin allow SSRF
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-27205
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:extended-choice-parameter
                        
                        (Maven)
                      Mar 16, 2022 
                    
                  
                    
                      Missing permission checks in Jenkins kubernetes-cd Plugin allow enumerating credentials IDs
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-27209
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:kubernetes-cd
                        
                        (Maven)
                      Mar 16, 2022 
                    
                  
                    
                      Missing permission checks in Jenkins Release Helper Plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-27215
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:release-helper
                        
                        (Maven)
                      Mar 16, 2022 
                    
                  
                    
                      CSRF vulnerability and missing permission checks in Jenkins kubernetes-cd Plugin allow capturing credentials
                    
                      
  High
                    
                
                      
                        CVE-2022-27211
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:kubernetes-cd
                        
                        (Maven)
                      Mar 16, 2022 
                    
                  
                    
                      The Meks Easy Photo Feed Widget WordPress plugin before 1.2.4 does not have capability and CSRF...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-24958
                      
                      was published
                      Mar 15, 2022 
                    
                  
                    
                      The Insight Core WordPress plugin through 1.0 does not have any authorisation and CSRF checks in...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-24950
                      
                      was published
                      Mar 15, 2022 
                    
                  
                    
                      Gogs vulnerable to improper PAM authorization handling
                    
                      
  High
                    
                
                      
                        CVE-2022-0871
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Mar 14, 2022 
                    
                  
                    
                      Duplicate Advisory: Improper Authorization in Gogs
                    
                      
  High
                    
                
                      
                        GHSA-65f3-3278-7m65
                      
                      was published
                        for
                        
                          gogs.io/gogs
                        
                        (Go)
                      Mar 12, 2022 
                        •
                        
                          withdrawn
                    
                  
                    
                      saleor Missing Authorization vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0932
                      
                      was published
                        for
                        
                          saleor
                        
                        (pip)
                      Mar 12, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API