GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
IBM PowerSC 1.3, 2.0, and 2.1 uses Cross-Origin Resource Sharing (CORS) which could allow an...
Moderate
Unreviewed
CVE-2023-50940
was published
Feb 2, 2024
Microsoft Edge for Android Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-21382
was published
Jan 26, 2024
A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All...
High
Unreviewed
CVE-2023-46281
was published
Dec 12, 2023
A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 ...
Moderate
Unreviewed
CVE-2023-25603
was published
Nov 14, 2023
A vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the...
High
Unreviewed
CVE-2023-46098
was published
Nov 14, 2023
Sensitive information disclosure due to CORS misconfiguration. The following products are...
Low
Unreviewed
CVE-2023-2360
was published
Apr 28, 2023
Media CP Media Control Panel latest version. A Permissive Flash Cross-domain Policy may allow...
High
Unreviewed
CVE-2023-23464
was published
Feb 15, 2023
Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS).
High
Unreviewed
CVE-2022-47717
was published
Feb 1, 2023
Connectwise Control 22.8.10013.8329 is vulnerable to Cross Origin Resource Sharing (CORS).
Moderate
Unreviewed
CVE-2023-23128
was published
Feb 1, 2023
A malicious website could have learned the size of a cross-origin resource that supported Range...
Critical
Unreviewed
CVE-2022-31736
was published
Dec 22, 2022
Insecure default value for CORS configuration
Critical
CVE-2022-26969
was published
for
directus
(npm)
Apr 5, 2022
A CWE-942: Permissive Cross-domain Policy with Untrusted Domains vulnerability exists that could...
High
Unreviewed
CVE-2022-22808
was published
Feb 11, 2022
Remote code execution in Eclipse Theia
High
CVE-2021-34435
was published
for
@theia/mini-browser
(npm)
Sep 2, 2021
ProTip!
Advisories are also available from the
GraphQL API