GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
301 advisories
Filter by severity
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could...
Moderate
Unreviewed
CVE-2023-20152
was published
Apr 5, 2023
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could...
Moderate
Unreviewed
CVE-2023-20021
was published
Apr 5, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43627
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43628
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43626
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43624
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43631
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43629
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43632
was published
Mar 29, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected...
Moderate
Unreviewed
CVE-2022-43633
was published
Mar 29, 2023
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote...
Moderate
Unreviewed
CVE-2023-20075
was published
Mar 1, 2023
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security...
Moderate
Unreviewed
CVE-2023-20015
was published
Feb 23, 2023
In cmd services, there is a OS command injection issue due to missing permission check. This...
Moderate
Unreviewed
CVE-2022-47339
was published
Feb 12, 2023
Buffalo network devices WSR-3200AX4S firmware Ver. 1.26 and earlier, WSR-3200AX4B firmware Ver. 1...
Moderate
Unreviewed
CVE-2022-43466
was published
Dec 19, 2022
PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 was discovered to be vulnerable to...
Moderate
Unreviewed
CVE-2022-26580
was published
Dec 17, 2022
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS...
Moderate
Unreviewed
CVE-2022-20934
was published
Nov 16, 2022
SAP GUI allows an authenticated attacker to execute scripts in the local network. On successful...
Moderate
Unreviewed
CVE-2022-41205
was published
Nov 9, 2022
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A...
Moderate
Unreviewed
CVE-2022-34437
was published
Oct 21, 2022
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2022-20930
was published
Oct 1, 2022
A vulnerability in the self-healing functionality of Cisco IOS XE Software for Embedded Wireless...
Moderate
Unreviewed
CVE-2022-20855
was published
Oct 1, 2022
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2022-20865
was published
Aug 26, 2022
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the...
Moderate
Unreviewed
CVE-2022-34769
was published
Aug 6, 2022
IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code...
Moderate
Unreviewed
CVE-2022-33955
was published
Aug 2, 2022
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated...
Moderate
Unreviewed
CVE-2022-22555
was published
Jul 22, 2022
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via...
Moderate
Unreviewed
CVE-2019-18424
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API