GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,501
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
125 advisories
Filter by severity
Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt...
Moderate
Unreviewed
CVE-2023-31356
was published
Aug 13, 2024
Incomplete cleanup when performing redactions in Conduit, allowing an attacker to check whether...
Low
Unreviewed
CVE-2024-6300
was published
Jun 25, 2024
Moodle HTTP authorization header is preserved between "emulated redirects"
Moderate
CVE-2024-38275
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
In the Linux kernel, the following vulnerability has been resolved:
afs: Fix page leak
There's...
Moderate
Unreviewed
CVE-2021-47365
was published
May 21, 2024
Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an...
Moderate
Unreviewed
CVE-2023-45846
was published
May 16, 2024
If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not...
Moderate
Unreviewed
CVE-2024-4767
was published
May 14, 2024
In the Linux kernel, the following vulnerability has been resolved:
mm: zswap: fix missing folio...
Moderate
Unreviewed
CVE-2024-26832
was published
Apr 17, 2024
In the Linux kernel, the following vulnerability has been resolved:
LoongArch: Update...
Moderate
Unreviewed
CVE-2024-26841
was published
Apr 17, 2024
In the Linux kernel, the following vulnerability has been resolved:
nfc: nci: free...
Moderate
Unreviewed
CVE-2024-26825
was published
Apr 17, 2024
In the Linux kernel, the following vulnerability has been resolved:
net: veth: clear GRO when...
Moderate
Unreviewed
CVE-2024-26803
was published
Apr 4, 2024
In the Linux kernel, the following vulnerability has been resolved:
md: Don't register...
Moderate
Unreviewed
CVE-2024-26756
was published
Apr 3, 2024
In the Linux kernel, the following vulnerability has been resolved:
xen/events: close evtchn...
Moderate
Unreviewed
CVE-2024-26687
was published
Apr 3, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/msm/dpu: check for valid...
Moderate
Unreviewed
CVE-2024-26667
was published
Apr 2, 2024
A vulnerability in the multicast DNS (mDNS) gateway feature of Cisco IOS XE Software for Wireless...
High
Unreviewed
CVE-2024-20303
was published
Mar 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Avoid...
Moderate
Unreviewed
CVE-2021-47178
was published
Mar 25, 2024
In the Linux kernel, the following vulnerability has been resolved:
net/smc: remove device from...
Moderate
Unreviewed
CVE-2021-47143
was published
Mar 25, 2024
In the Linux kernel, the following vulnerability has been resolved:
PCI: switchtec: Fix...
Moderate
Unreviewed
CVE-2023-52617
was published
Mar 18, 2024
In the Linux kernel, the following vulnerability has been resolved:
x86/kvm: Disable kvmclock on...
High
Unreviewed
CVE-2021-47110
was published
Mar 15, 2024
Improper cleanup in temporary file handling component in Devolutions Remote Desktop Manager 2024...
Moderate
Unreviewed
CVE-2024-2403
was published
Mar 13, 2024
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Moderate
CVE-2024-23672
was published
for
org.apache.tomcat.embed:tomcat-embed-websocket
(Maven)
Mar 13, 2024
An unauthenticated remote attacker can gain service level privileges through an incomplete...
Moderate
Unreviewed
CVE-2024-26005
was published
Mar 12, 2024
A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865,...
Low
Unreviewed
CVE-2024-1048
was published
Feb 6, 2024
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper...
Moderate
Unreviewed
CVE-2024-21617
was published
Jan 12, 2024
Apache Struts Improper Control of Dynamically-Managed Code Resources vulnerability
High
CVE-2023-41835
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 5, 2023
Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially...
Low
Unreviewed
CVE-2022-46298
was published
Nov 14, 2023
ProTip!
Advisories are also available from the
GraphQL API