GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
12,432 advisories
Filter by severity
Admidio Vulnerable to HTML Injection In The Messages Section
Low
CVE-2024-47836
was published
for
admidio/admidio
(Composer)
Oct 16, 2024
Plone Denial of Service vulnerability via decompressing large zip archives
Low
CVE-2013-4199
was published
for
plone
(pip)
May 17, 2022
Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier...
Low
Unreviewed
CVE-2024-46897
was published
Oct 18, 2024
Plone Multiple open redirect vulnerabilities
Low
CVE-2013-4195
was published
for
plone
(pip)
May 17, 2022
A vulnerability classified as problematic has been found in Beijing Baichuo Smart S150 Management...
Low
Unreviewed
CVE-2024-0716
was published
Jan 19, 2024
Mozilla Firefox before 34.0, Firefox ESR 31.x before 31.3, and Thunderbird before 31.3 on Apple...
Low
Unreviewed
CVE-2014-1595
was published
May 17, 2022
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4211
was published
Oct 16, 2024
Improper Validation of Specified Quantity in Input vulnerability in OpenText OpenText Application...
Low
Unreviewed
CVE-2024-4692
was published
Oct 16, 2024
RPLY Predictable Tmpfile Names Allows Cache Spoofing
Low
CVE-2014-1604
was published
for
RPLY
(pip)
May 17, 2022
Salt uses weak permissions on the cache data
Low
CVE-2015-8034
was published
for
salt
(pip)
May 17, 2022
SaltStack Salt Improper Authentication via Man in the Middle Attack
Low
CVE-2022-22935
was published
for
salt
(pip)
Mar 30, 2022
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker...
Low
Unreviewed
CVE-2024-47486
was published
Oct 18, 2024
IBM Concert 1.0.0 and 1.0.1 vulnerable to attacks that rely on the use of cookies without the...
Low
Unreviewed
CVE-2024-43173
was published
Oct 22, 2024
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR...
Low
Unreviewed
CVE-2015-4481
was published
May 14, 2022
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: don't use...
Low
Unreviewed
CVE-2024-47738
was published
Oct 21, 2024
HCL Sametime is impacted by the error messages containing sensitive information. An attacker can...
Low
Unreviewed
CVE-2023-50355
was published
Oct 24, 2024
A vulnerability was found in code-projects Dormitory Management System 1.0. It has been rated as...
Low
Unreviewed
CVE-2024-0472
was published
Jan 13, 2024
In the Linux kernel, the following vulnerability has been resolved:
usb: typec: tipd: Free IRQ...
Low
Unreviewed
CVE-2024-50057
was published
Oct 21, 2024
AWS Load Balancer Controller automatically detaches externally associated web ACL from Application Load Balancers
Low
GHSA-rjfv-pjvx-mjgv
was published
for
sigs.k8s.io/aws-load-balancer-controller
(Go)
Oct 24, 2024
ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
Low
CVE-2024-9506
was published
for
vue
(npm)
Oct 15, 2024
Forwarding of confidentials headers to third parties in fluture-node
Low
CVE-2022-24719
was published
for
fluture-node
(npm)
Mar 1, 2022
A vulnerability classified as problematic was found in chidiwilliams buzz 1.1.0. This...
Low
Unreviewed
CVE-2024-10372
was published
Oct 25, 2024
Dell Data Lakehouse, version(s) 1.0.0.0 and 1.1.0.0, contain(s) an Improper Neutralization of...
Low
Unreviewed
CVE-2024-47483
was published
Oct 25, 2024
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
Low
CVE-2014-0105
was published
for
python-keystoneclient
(pip)
May 17, 2022
In the Linux kernel, the following vulnerability has been resolved:
udf: Fix bogus checksum...
Low
Unreviewed
CVE-2024-43845
was published
Aug 17, 2024
ProTip!
Advisories are also available from the
GraphQL API