GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
439 advisories
Filter by severity
PGP Security PGPfire 7.1 for Windows alters the system's TCP/IP stack and modifies packets in...
Moderate
Unreviewed
CVE-2002-0208
was published
Apr 30, 2022
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine...
Moderate
Unreviewed
CVE-2001-1483
was published
Apr 30, 2022
AmTote International homebet program returns different error messages when invalid account...
Moderate
Unreviewed
CVE-2001-1528
was published
Apr 30, 2022
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client...
Moderate
Unreviewed
CVE-2000-1117
was published
Apr 30, 2022
Windows Cryptographic Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2025-21336
was published
Jan 14, 2025
IBM InfoSphere Information Server 11.7
could allow an authenticated to obtain sensitive...
Moderate
Unreviewed
CVE-2024-51477
was published
Mar 29, 2025
An issue was discovered in OpenSlides before 4.2.5. During login at the /system/auth/login/...
Moderate
Unreviewed
CVE-2025-30344
was published
Mar 21, 2025
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP...
Moderate
Unreviewed
CVE-2022-48220
was published
Feb 15, 2024
In reload of ServiceListing.java , there is a possible way to allow a malicious app to hide an...
Moderate
Unreviewed
CVE-2024-49733
was published
Jan 22, 2025
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To...
Moderate
Unreviewed
CVE-2020-12413
was published
Feb 17, 2023
Post-Quantum Secure Feldman's Verifiable Secret Sharing has Timing Side-Channels in Matrix Operations
Moderate
CVE-2025-29780
was published
for
PostQuantum-Feldman-VSS
(pip)
Mar 14, 2025
In build_read_multi_rsp of gatt_sr.cc, there is a possible denial of service due to a logic error...
Moderate
Unreviewed
CVE-2024-43763
was published
Jan 22, 2025
A website was able to detect when a user took a screenshot of a page using the built-in...
Moderate
Unreviewed
CVE-2024-5697
was published
Jun 11, 2024
Observable Response Discrepancy in Flask-AppBuilder
Moderate
CVE-2022-21659
was published
for
Flask-AppBuilder
(pip)
Feb 1, 2022
Observable Response Discrepancy in Flask-AppBuilder
Moderate
CVE-2021-29621
was published
for
Flask-AppBuilder
(pip)
May 27, 2021
User account enumeration in eZ Publish Ibexa Kernel
Moderate
CVE-2021-46876
was published
for
ezsystems/ezpublish-kernel
(Composer)
Mar 12, 2023
IBM Sterling File Gateway 6.0.0.0 through 6.1.2.5 and 6.2.0.0 through 6.2.0.1 could allow an...
Moderate
Unreviewed
CVE-2023-47159
was published
Jan 27, 2025
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an...
Moderate
Unreviewed
CVE-2023-37413
was published
Jan 29, 2025
ginuerzh/gost vulnerable to Timing Attack
Moderate
CVE-2023-32691
was published
for
github.com/ginuerzh/gost
(Go)
May 22, 2023
IBM Control Center 6.2.1 and 6.3.1
could allow a remote attacker to enumerate usernames due...
Moderate
Unreviewed
CVE-2024-35114
was published
Jan 25, 2025
openssl-src subject to Timing Oracle in RSA Decryption
Moderate
CVE-2022-4304
was published
for
openssl-src
(Rust)
Feb 8, 2023
Possible Information Leak / Session Hijack Vulnerability in Rack
Moderate
CVE-2019-16782
was published
for
rack
(RubyGems)
Dec 18, 2019
User enumeration in On-premise SureMDM Solution on Windows deployment allows attacker to...
Moderate
Unreviewed
CVE-2023-3897
was published
Jul 25, 2023
IBM Common Licensing 9.0 could allow a local user to enumerate usernames due to an observable...
Moderate
Unreviewed
CVE-2023-50306
was published
Feb 20, 2024
The login functionality of the web server in affected devices does not normalize the response...
Moderate
Unreviewed
CVE-2023-37482
was published
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API