GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
248 advisories
Filter by severity
In Red Hat Advanced Cluster Security (RHACS), it was found that some security related HTTP...
Moderate
Unreviewed
CVE-2023-4958
was published
Dec 12, 2023
Jenkins REST APIs vulnerable to clickjacking
Low
CVE-2020-2105
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 24, 2022
An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via...
Moderate
Unreviewed
CVE-2023-47311
was published
Nov 20, 2023
An Improper Restriction of Rendered UI Layers or Frames in the Schweitzer Engineering...
Moderate
Unreviewed
CVE-2023-2265
was published
Nov 30, 2023
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking...
Moderate
Unreviewed
CVE-2023-6206
was published
Nov 21, 2023
A flaw was found in Quay. Clickjacking is when an attacker uses multiple transparent or opaque...
Moderate
Unreviewed
CVE-2023-4956
was published
Nov 7, 2023
It was possible for certain browser prompts and dialogs to be activated or dismissed...
Moderate
Unreviewed
CVE-2023-5721
was published
Oct 25, 2023
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10,...
Moderate
Unreviewed
CVE-2023-36920
was published
Oct 30, 2023
Economizzer vulnerable to Clickjacking
Moderate
CVE-2023-38873
was published
for
gugoan/economizzer
(Composer)
Sep 28, 2023
A vulnerability in the web UI of Gurock TestRail v5.3.0.3603 could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2021-37788
was published
May 24, 2022
A missing HTTP header (X-Frame-Options) in Kiwi Syslog Server has left customers vulnerable to...
Moderate
Unreviewed
CVE-2021-35237
was published
May 24, 2022
Multiple vulnerabilities in the web interface of Cisco Webex Meetings could allow a remote...
Moderate
Unreviewed
CVE-2022-20852
was published
Aug 11, 2022
The issue was addressed with improved UI handling. This issue is fixed in Safari 16, tvOS 16,...
Moderate
Unreviewed
CVE-2022-32891
was published
Feb 27, 2023
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS...
Moderate
Unreviewed
CVE-2022-42799
was published
Nov 2, 2022
An attacker could trick a user of Hitachi ABB Power Grids Ellipse Enterprise Asset Management ...
Moderate
Unreviewed
CVE-2021-27414
was published
Mar 12, 2022
For ABB eSOMS versions 4.0 to 6.0.2, the X-Frame-Options header is not configured in HTTP...
Moderate
Unreviewed
CVE-2019-19001
was published
May 24, 2022
Improper Restriction of Rendered UI Layers or Frames in GitHub repository unilogies/bumsys prior...
Moderate
Unreviewed
CVE-2023-1362
was published
Mar 13, 2023
Western Digital My Cloud Home and ibi devices before 2.2.0 allow clickjacking on sign-in pages.
Moderate
Unreviewed
CVE-2020-10951
was published
May 24, 2022
Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit
Moderate
CVE-2023-0780
was published
for
cockpit-hq/cockpit
(Composer)
Feb 11, 2023
Connectwise Automate 2022.11 is vulnerable to Clickjacking. The login screen can be iframed and...
Moderate
Unreviewed
CVE-2023-23126
was published
Feb 1, 2023
Dell PowerScale OneFS, 8.2.0 through 9.3.0, contain an User Interface Security Issue. An...
Moderate
Unreviewed
CVE-2022-45096
was published
Feb 1, 2023
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in...
Moderate
Unreviewed
CVE-2020-10743
was published
May 24, 2022
In onCreate of PhoneAccountSettingsActivity.java and related files, there is a possible way to...
High
Unreviewed
CVE-2023-20913
was published
Jan 26, 2023
Cockpit (and its plugins) do not seem to protect itself against clickjacking. It is possible to...
Moderate
Unreviewed
CVE-2021-3660
was published
Mar 11, 2022
Improper Restriction of Rendered UI Layers or Frames vulnerability in Mitsubishi Electric...
Moderate
Unreviewed
CVE-2022-40268
was published
Feb 2, 2023
ProTip!
Advisories are also available from the
GraphQL API