GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287,862 advisories
Filter by severity
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a...
Critical
Unreviewed
CVE-2022-30877
was published
Jun 9, 2022
Apache Helix UI vulnerable to Open Redirect
Moderate
CVE-2022-47500
was published
for
org.apache.helix:helix
(Maven)
Dec 19, 2022
Multiple cross-site scripting (XSS) vulnerabilities in ocsreports/index.php in OCS Inventory NG 1...
Moderate
Unreviewed
CVE-2010-1594
was published
May 17, 2022
SQL injection vulnerability in Mahara 1.1.x before 1.1.9 and 1.2.x before 1.2.5 allows remote...
High
Unreviewed
CVE-2010-1669
was published
May 17, 2022
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the...
Moderate
Unreviewed
CVE-2017-8642
was published
May 17, 2022
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3...
Moderate
Unreviewed
CVE-2010-1658
was published
May 17, 2022
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an...
High
Unreviewed
CVE-2016-9981
was published
May 17, 2022
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5...
High
Unreviewed
CVE-2014-8903
was published
May 17, 2022
Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold,...
High
Unreviewed
CVE-2017-8664
was published
May 17, 2022
Microsoft Edge in Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute...
High
Unreviewed
CVE-2017-8639
was published
May 17, 2022
Windows Subsystem for Linux in Windows 10 1703, allows a denial of service vulnerability due to...
Moderate
Unreviewed
CVE-2017-8627
was published
May 17, 2022
A length validation (leading to out-of-bounds read and write) flaw was found in the way...
High
Unreviewed
CVE-2017-11670
was published
May 17, 2022
openibd in OpenFabrics Enterprise Distribution (OFED) 1.5.2 allows local users to overwrite...
Moderate
Unreviewed
CVE-2010-1693
was published
May 17, 2022
Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools)...
Moderate
Unreviewed
CVE-2010-1547
was published
May 17, 2022
SQL injection exists in Quest KACE Asset Management Appliance 6.4.120822 through 7.2, Systems...
Critical
Unreviewed
CVE-2017-12567
was published
May 17, 2022
Information exposure vulnerability in SemIWCMonitor prior to SMR Jun-2022 Release 1 allows local...
Low
Unreviewed
CVE-2022-30714
was published
Jun 8, 2022
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows...
Critical
Unreviewed
CVE-2022-30722
was published
Jun 8, 2022
Improper access control vulnerability in Smart Things prior to 1.7.85.25 allows local attackers...
High
Unreviewed
CVE-2022-30749
was published
Jun 8, 2022
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022...
Moderate
Unreviewed
CVE-2022-30719
was published
Jun 8, 2022
A vulnerability was found in Brandbugle. It has been rated as critical. Affected by this issue is...
High
Unreviewed
CVE-2020-36536
was published
Jun 8, 2022
A vulnerability, which was classified as critical, has been found in SevOne Network Management...
High
Unreviewed
CVE-2020-36531
was published
Jun 8, 2022
Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD...
High
Unreviewed
CVE-2022-24296
was published
Jun 9, 2022
Cross-site Scripting in Dolibarr
Moderate
CVE-2022-30875
was published
for
dolibarr/dolibarr
(Composer)
Jun 9, 2022
A vulnerability was found in Lógico y Creativo 1.0 and classified as critical. This issue affects...
Critical
Unreviewed
CVE-2020-36539
was published
Jun 8, 2022
OS Command Injection in file editor in Gogs
Critical
CVE-2022-1986
was published
for
gogs.io/gogs
(Go)
Jun 8, 2022
ProTip!
Advisories are also available from the
GraphQL API