GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
460 advisories
Filter by severity
Apache Struts RCE Vulnerability
High
CVE-2016-0785
was published
for
org.apache.struts:struts2-core
(Maven)
May 14, 2022
RubyGems may allow a maliciously crafted gem to overwrite files
High
CVE-2017-0901
was published
for
rubygems-update
(RubyGems)
May 13, 2022
Improper Input Validation in Datomic
High
CVE-2018-10054
was published
for
com.datomic:datomic-free
(Maven)
May 13, 2022
Improper Input Validation in Apache Struts
High
CVE-2016-1181
was published
for
org.apache.struts:struts-core
(Maven)
May 13, 2022
Improper Input Validation in Apache Struts
High
CVE-2016-1182
was published
for
org.apache.struts:struts-core
(Maven)
May 13, 2022
Mercurial Improper Input Validation vulnerability
High
CVE-2018-13346
was published
for
mercurial
(pip)
May 13, 2022
Mercurial Improper Input Validation vulnerability
High
CVE-2018-13348
was published
for
mercurial
(pip)
May 13, 2022
Improper Input Validation in Apache Tomcat
High
CVE-2016-6816
was published
for
org.apache.tomcat:tomcat-coyote
(Maven)
May 13, 2022
Code injection in Apache Struts
High
CVE-2013-2251
was published
for
org.apache.struts:struts2-core
(Maven)
May 13, 2022
Improper Input Validation in BeanShell
High
CVE-2016-2510
was published
for
org.apache-extras.beanshell:bsh
(Maven)
May 13, 2022
Moodle XSS Vulnerability
High
CVE-2018-10891
was published
for
moodle/moodle
(Composer)
May 13, 2022
open-uri-cached Gem for Ruby Unsafe Temporary File Creation Enables Code Execution
High
CVE-2015-3649
was published
for
open-uri-cached
(RubyGems)
May 13, 2022
Improper Input Validation in Apache CXF
High
CVE-2010-2076
was published
for
org.apache.cxf:cxf-rt-frontend-jaxrs
(Maven)
May 13, 2022
Remote web-service operation execution in Apache CXF
High
CVE-2012-3451
was published
for
org.apache.cxf:cxf
(Maven)
May 13, 2022
Improper Input Validation in Apache Hadoop
High
CVE-2017-3162
was published
for
org.apache.hadoop:hadoop-client
(Maven)
May 13, 2022
Apache Qpid Python client Improper certificate validation
High
CVE-2013-1909
was published
for
qpid-python
(pip)
May 13, 2022
Ansible Improper Input Validation vulnerability
High
CVE-2018-10874
was published
for
ansible
(pip)
May 13, 2022
OpensStack Neutron Denial of Service Vulnerability
High
CVE-2018-14635
was published
for
neutron
(pip)
May 13, 2022
Improper Input Validation in Jenkins
High
CVE-2018-1999002
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Improper Input Validation in Jenkins
High
CVE-2018-1999001
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Improper Input Validation in k8s.io/ingress-nginx
High
CVE-2021-25745
was published
for
k8s.io/ingress-nginx
(Go)
May 7, 2022
Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
High
CVE-2013-4751
was published
for
symfony/symfony
(Composer)
May 5, 2022
ProTip!
Advisories are also available from the
GraphQL API