GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned...
Moderate
Unreviewed
CVE-2018-20934
was published
May 24, 2022
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents...
High
Unreviewed
CVE-2016-10825
was published
May 24, 2022
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4...
High
Unreviewed
CVE-2018-16860
was published
May 24, 2022
Improperly Implemented Security Check for Standard in org.springframework:spring-core
Critical
CVE-2018-1275
was published
for
org.springframework:spring-core
(Maven)
Oct 17, 2018
Client Spoofing within the Keycloak Device Authorisation Grant
Low
CVE-2023-2585
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Jun 30, 2023
Inconsistent documentation in Apache Tomcat
Moderate
CVE-2017-15706
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Java: DoS Vulnerability in JSON-JAVA
High
CVE-2023-5072
was published
for
org.json:json
(Maven)
Nov 14, 2023
vantage6-server node accepts non-whitelisted algorithms from malicious server
High
CVE-2023-47631
was published
for
vantage6-server
(pip)
Nov 14, 2023
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address...
Moderate
Unreviewed
CVE-2021-34790
was published
May 24, 2022
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address...
Moderate
Unreviewed
CVE-2021-34791
was published
May 24, 2022
In marshmallow library the schema "only" option treats an empty list as implying no "only" option
Moderate
CVE-2018-17175
was published
for
marshmallow
(pip)
Oct 10, 2018
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
Moderate
Unreviewed
CVE-2021-42017
was published
Mar 9, 2022
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to...
Moderate
Unreviewed
CVE-2016-8635
was published
May 13, 2022
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager...
High
Unreviewed
CVE-2019-14823
was published
May 24, 2022
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in...
Moderate
Unreviewed
CVE-2020-10743
was published
May 24, 2022
Huawei Honor 5S smart phones with software the versions before TAG-TL00C01B173 have a Factory...
Moderate
Unreviewed
CVE-2017-8152
was published
May 17, 2022
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service...
High
Unreviewed
CVE-2017-15665
was published
May 14, 2022
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of...
High
Unreviewed
CVE-2017-15664
was published
May 14, 2022
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service...
High
Unreviewed
CVE-2017-15663
was published
May 14, 2022
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service...
High
Unreviewed
CVE-2017-15662
was published
May 14, 2022
Suricata before 3.2.1 has an IPv4 defragmentation evasion issue caused by lack of a check for the...
High
Unreviewed
CVE-2017-7177
was published
May 14, 2022
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP...
Critical
Unreviewed
CVE-2016-10229
was published
May 17, 2022
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS...
Moderate
Unreviewed
CVE-2017-12303
was published
May 13, 2022
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4...
High
Unreviewed
CVE-2017-15091
was published
May 13, 2022
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus...
Moderate
Unreviewed
CVE-2017-6032
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API