GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
111,584 advisories
Filter by severity
Directory traversal vulnerability in the FTP server on Honeywell Excel Web XL1000C50 52 I/O,...
High
Unreviewed
CVE-2015-0984
was published
May 17, 2022
The WPML plugin before 3.1.9 for WordPress does not properly handle multiple actions in a request...
High
Unreviewed
CVE-2015-2792
was published
May 17, 2022
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows...
High
Unreviewed
CVE-2015-1815
was published
May 17, 2022
Unspecified vulnerability in MyBB (aka MyBulletinBoard) before 1.8.4 has unknown attack vectors...
High
Unreviewed
CVE-2015-2786
was published
May 17, 2022
HP TippingPoint Security Management System (SMS) and TippingPoint Virtual Security Management...
High
Unreviewed
CVE-2015-2117
was published
May 17, 2022
Stack-based buffer overflow in the PmBase64Decode function in an unspecified demonstration...
High
Unreviewed
CVE-2014-9205
was published
May 17, 2022
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote...
High
Unreviewed
CVE-2015-2284
was published
May 17, 2022
Unrestricted file upload vulnerability in sam-ajax-admin.php in the Simple Ads Manager plugin...
High
Unreviewed
CVE-2015-2825
was published
May 17, 2022
Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet)...
High
Unreviewed
CVE-2014-5370
was published
May 17, 2022
Multiple SQL injection vulnerabilities in the Web-Dorado ECommerce WD (com_ecommercewd) component...
High
Unreviewed
CVE-2015-2562
was published
May 17, 2022
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x...
High
Unreviewed
CVE-2015-1804
was published
May 17, 2022
The bdfReadProperties function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x...
High
Unreviewed
CVE-2015-1802
was published
May 17, 2022
The bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont before 1.4.9 and 1.5.x...
High
Unreviewed
CVE-2015-1803
was published
May 17, 2022
Integer underflow in the EVP_DecodeUpdate function in crypto/evp/encode.c in the base64-decoding...
High
Unreviewed
CVE-2015-0292
was published
May 17, 2022
SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote...
High
Unreviewed
CVE-2015-2563
was published
May 17, 2022
The cache handler in MyBB (aka MyBulletinBoard) before 1.8.4 does not properly check the encoding...
High
Unreviewed
CVE-2015-2352
was published
May 17, 2022
Use-after-free vulnerability in the sctp_assoc_update function in net/sctp/associola.c in the...
High
Unreviewed
CVE-2015-1421
was published
May 14, 2022
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does...
High
Unreviewed
CVE-2014-7822
was published
May 17, 2022
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers...
High
Unreviewed
CVE-2015-2314
was published
May 14, 2022
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X...
High
Unreviewed
CVE-2015-0336
was published
May 17, 2022
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X...
High
Unreviewed
CVE-2015-3042
was published
May 14, 2022
Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote...
High
Unreviewed
CVE-2015-2237
was published
May 14, 2022
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2...
High
Unreviewed
CVE-2015-0097
was published
May 14, 2022
The logrotation script (/etc/cron.daily/upstart) in the Ubuntu Upstart package before 1.13.2...
High
Unreviewed
CVE-2015-2285
was published
May 17, 2022
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier...
High
Unreviewed
CVE-2015-1875
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API