GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
140 advisories
Filter by severity
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A...
Moderate
Unreviewed
CVE-2020-7982
was published
May 24, 2022
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file...
Moderate
Unreviewed
CVE-2019-15613
was published
May 24, 2022
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could...
Moderate
Unreviewed
CVE-2023-0350
was published
Mar 13, 2023
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file...
Moderate
Unreviewed
CVE-2019-12804
was published
May 24, 2022
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30...
Moderate
Unreviewed
CVE-2023-21441
was published
Feb 9, 2023
Lack of proper validation of server UUID can be used by the server to trick the client to accept invalid proofs
Moderate
CVE-2022-39199
was published
for
github.com/codenotary/immudb
(Go)
Nov 21, 2022
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
Moderate
CVE-2015-0259
was published
for
nova
(pip)
May 14, 2022
It was found that a specially crafted LUKS header could trick cryptsetup into disabling...
Moderate
Unreviewed
CVE-2021-4122
was published
Aug 25, 2022
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to...
Moderate
Unreviewed
CVE-2021-24825
was published
Mar 8, 2022
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient...
Moderate
Unreviewed
CVE-2022-22567
was published
Feb 10, 2022
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a...
Moderate
Unreviewed
CVE-2021-26396
was published
Jan 11, 2023
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate...
Moderate
Unreviewed
CVE-2020-10137
was published
Jan 11, 2022
ReDoS in Sec-Websocket-Protocol header
Moderate
CVE-2021-32640
was published
for
ws
(npm)
May 28, 2021
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for...
Moderate
Unreviewed
CVE-2015-9232
was published
May 17, 2022
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker...
Moderate
Unreviewed
CVE-2017-2701
was published
May 17, 2022
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle...
Moderate
Unreviewed
CVE-2017-1773
was published
May 14, 2022
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote...
Moderate
Unreviewed
CVE-2015-0251
was published
May 14, 2022
A content spoofing vulnerability in the following components allows to render html pages...
Moderate
Unreviewed
CVE-2018-2434
was published
May 13, 2022
An issue existed in the handling of iMessage tapbacks. The issue was resolved with additional...
Moderate
Unreviewed
CVE-2020-9885
was published
May 24, 2022
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software...
Moderate
Unreviewed
CVE-2017-12740
was published
May 13, 2022
IBM Security Identity Manager Virtual Appliance 7.0 processes patches, image backups and other...
Moderate
Unreviewed
CVE-2017-1405
was published
May 13, 2022
A vulnerability was discovered in all versions of Medtronic MyCareLink 24950 and 24952 Patient...
Moderate
Unreviewed
CVE-2018-10626
was published
May 13, 2022
Improperly Implemented path matching for in-toto-golang
Moderate
CVE-2021-41087
was published
for
github.com/in-toto/in-toto-golang
(Go)
Sep 22, 2021
Denial of Service in SheetJS Pro
Moderate
CVE-2021-32014
was published
for
org.webjars.npm:xlsx
(Maven)
Jul 22, 2021
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
Moderate
Unreviewed
CVE-2018-17938
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API