GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,802
Erlang
36
GitHub Actions
29
Go
2,386
Maven
5,000+
npm
4,016
NuGet
720
pip
3,811
Pub
12
RubyGems
930
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
22,907 advisories
Filter by severity
Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which...
Critical
Unreviewed
CVE-2022-36555
was published
Aug 30, 2022
A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec...
Critical
Unreviewed
CVE-2022-36554
was published
Aug 30, 2022
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-36559
was published
Aug 30, 2022
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root...
Critical
Unreviewed
CVE-2022-36558
was published
Aug 30, 2022
Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded...
Critical
Unreviewed
CVE-2022-36560
was published
Aug 30, 2022
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload...
Critical
Unreviewed
CVE-2022-36557
was published
Aug 30, 2022
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-36556
was published
Aug 30, 2022
Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-36553
was published
Aug 30, 2022
Sinsiu Sinsiu Enterprise Website System v1.1.1.0 was discovered to contain a remote code...
Critical
Unreviewed
CVE-2022-36572
was published
Aug 29, 2022
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910...
Critical
Unreviewed
CVE-2022-32548
was published
Aug 29, 2022
A SQL injection vulnerability in the product_all_one_img and image_product parameters of the...
Critical
Unreviewed
CVE-2022-22897
was published
Aug 29, 2022
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to Buffer...
Critical
Unreviewed
CVE-2022-37055
was published
Aug 29, 2022
D-Link GO-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 is vulnerable to Command...
Critical
Unreviewed
CVE-2022-37056
was published
Aug 29, 2022
D-Link Go-RT-AC750 GORTAC750_revA_v101b03 and GO-RT-AC750_revB_FWv200b02 are vulnerable to...
Critical
Unreviewed
CVE-2022-37057
was published
Aug 29, 2022
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
Critical
Unreviewed
CVE-2022-36756
was published
Aug 29, 2022
D-Link DIR845L A1 contains a authentication vulnerability via an AUTHORIZED_GROUP=1 value, as...
Critical
Unreviewed
CVE-2022-36755
was published
Aug 29, 2022
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability...
Critical
Unreviewed
CVE-2022-36705
was published
Aug 29, 2022
Linksys E1200 v1.0.04 is vulnerable to Buffer Overflow via ej_get_web_page_name.
Critical
Unreviewed
CVE-2022-38555
was published
Aug 29, 2022
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
Critical
Unreviewed
CVE-2022-37053
was published
Aug 29, 2022
Trendnet TEW733GR v1.03B01 contains a Static Default Credential vulnerability in /etc/init0.d...
Critical
Unreviewed
CVE-2022-38556
was published
Aug 29, 2022
D-Link DIR845L v1.00-v1.03 contains a Static Default Credential vulnerability in /etc/init0.d...
Critical
Unreviewed
CVE-2022-38557
was published
Aug 29, 2022
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the Id...
Critical
Unreviewed
CVE-2022-36708
was published
Aug 29, 2022
Ingredients Stock Management System v1.0 was discovered to contain a SQL injection vulnerability...
Critical
Unreviewed
CVE-2022-36706
was published
Aug 29, 2022
A vulnerability classified as critical has been found in SourceCodester Simple Task Managing...
Critical
Unreviewed
CVE-2022-3013
was published
Aug 28, 2022
The VRRP parser in tcpdump before 4.9.3 has a buffer over-read in print-vrrp.c:vrrp_print() for...
Critical
Unreviewed
CVE-2019-15167
was published
Aug 28, 2022
ProTip!
Advisories are also available from the
GraphQL API