GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,142 advisories
Filter by severity
The Trading 212 FOREX (aka com.avuscapital.trading212) application before 2.0.9 for Android does...
Moderate
Unreviewed
CVE-2014-5578
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory...
Moderate
Unreviewed
CVE-2014-5212
was published
May 17, 2022
The default AFSecurityPolicy.validatesDomainName configuration for AFSSLPinningModeNone in the...
Moderate
Unreviewed
CVE-2015-3996
was published
May 17, 2022
Unspecified vulnerability in the Oracle Applications Technology component in Oracle E-Business...
Moderate
Unreviewed
CVE-2014-6479
was published
May 17, 2022
The WebView class in the Cybozu Live application before 2.0.1 for Android allows attackers to...
Moderate
Unreviewed
CVE-2013-3647
was published
May 17, 2022
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11...
Moderate
Unreviewed
CVE-2014-4300
was published
May 17, 2022
The virtual filesystem in ownCloud Server before 6.0.9, 7.0.x before 7.0.7, and 8.0.x before 8.0...
Moderate
Unreviewed
CVE-2015-5954
was published
May 17, 2022
Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 provides different...
Moderate
Unreviewed
CVE-2015-7902
was published
May 17, 2022
Unspecified vulnerability in the Application Performance Management component in Oracle...
Moderate
Unreviewed
CVE-2014-6557
was published
May 17, 2022
The Cybozu Live application before 2.0.1 for Android allows remote attackers to execute arbitrary...
Moderate
Unreviewed
CVE-2013-3646
was published
May 17, 2022
Graphics Driver in Apple OS X before 10.9.4 does not properly restrict read operations during...
Moderate
Unreviewed
CVE-2014-1372
was published
May 17, 2022
WebKit in Apple Safari before 6.1.5 and 7.x before 7.0.5 allows user-assisted remote attackers to...
Moderate
Unreviewed
CVE-2014-1369
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability in Cisco Firepower Extensible Operating System 1...
Moderate
Unreviewed
CVE-2015-6373
was published
May 17, 2022
The web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000...
Moderate
Unreviewed
CVE-2015-6374
was published
May 17, 2022
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3,...
Moderate
Unreviewed
CVE-2014-6538
was published
May 17, 2022
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect availability...
Moderate
Unreviewed
CVE-2014-6490
was published
May 17, 2022
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply...
Moderate
Unreviewed
CVE-2014-6498
was published
May 17, 2022
Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 11.1...
Moderate
Unreviewed
CVE-2014-6462
was published
May 17, 2022
Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain...
Moderate
Unreviewed
CVE-2015-3270
was published
May 17, 2022
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to...
Moderate
Unreviewed
CVE-2015-7718
was published
May 17, 2022
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server ...
Moderate
Unreviewed
CVE-2014-0774
was published
May 17, 2022
Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003...
Moderate
Unreviewed
CVE-2015-6491
was published
May 17, 2022
The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents,...
Moderate
Unreviewed
CVE-2015-5661
was published
May 17, 2022
Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and...
Moderate
Unreviewed
CVE-2013-6975
was published
May 17, 2022
Unspecified vulnerability in the SQLJ component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11...
Moderate
Unreviewed
CVE-2014-6542
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API