GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
418 advisories
Filter by severity
totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive...
High
Unreviewed
CVE-2018-6562
was published
May 13, 2022
Huawei AppGallery versions before 8.0.4.301 has an arbitrary Javascript running vulnerability. An...
High
Unreviewed
CVE-2018-7932
was published
May 13, 2022
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient,...
High
Unreviewed
CVE-2022-26122
was published
Nov 2, 2022
The mod_dav_svn server in Subversion 1.5.0 through 1.7.19 and 1.8.0 through 1.8.11 allows remote...
Moderate
Unreviewed
CVE-2015-0251
was published
May 14, 2022
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it...
High
Unreviewed
CVE-2016-1493
was published
May 14, 2022
The autoupdate implementation in TimeDoctor Pro 1.4.72.3 on Windows relies on unsigned installer...
High
Unreviewed
CVE-2015-4674
was published
May 14, 2022
Secutech RiS-11, RiS-22, and RiS-33 devices with firmware V5.07.52_es_FRI01 allow DNS settings...
High
Unreviewed
CVE-2018-10080
was published
May 14, 2022
PackageKit's apt backend mistakenly treated all local debs as trusted. The apt security model is...
High
Unreviewed
CVE-2020-16122
was published
May 24, 2022
IBM DataPower Gateways 7.1, 7,2, 7.5, and 7.6 could allow an attacker using man-in-the-middle...
Moderate
Unreviewed
CVE-2017-1773
was published
May 14, 2022
A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific...
High
Unreviewed
CVE-2017-14091
was published
May 14, 2022
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker...
Moderate
Unreviewed
CVE-2017-2701
was published
May 17, 2022
The Good for Enterprise application 3.0.0.415 for Android does not use signature protection for...
Moderate
Unreviewed
CVE-2015-9232
was published
May 17, 2022
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3)....
High
Unreviewed
CVE-2022-36360
was published
Oct 11, 2022
ReDoS in Sec-Websocket-Protocol header
Moderate
CVE-2021-32640
was published
for
ws
(npm)
May 28, 2021
An arbitrary file download and execution vulnerability was found in the VideoOffice X2.9 and...
Critical
Unreviewed
CVE-2020-7878
was published
Dec 29, 2021
ASUS RT-AC68U, RT-AC66R, RT-AC66U, RT-AC56R, RT-AC56U, RT-N66R, RT-N66U, RT-N56R, RT-N56U, and...
High
Unreviewed
CVE-2014-2718
was published
May 17, 2022
Z-Wave devices based on Silicon Labs 700 series chipsets using S2 do not adequately authenticate...
Moderate
Unreviewed
CVE-2020-10137
was published
Jan 11, 2022
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a...
Moderate
Unreviewed
CVE-2021-26396
was published
Jan 11, 2023
A remote code execution vulnerability was discovered on Western Digital My Cloud devices where an...
Critical
Unreviewed
CVE-2022-22994
was published
Jan 29, 2022
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient...
Moderate
Unreviewed
CVE-2022-22567
was published
Feb 10, 2022
The Custom Content Shortcode WordPress plugin before 4.0.2 does not validate the data passed to...
Moderate
Unreviewed
CVE-2021-24825
was published
Mar 8, 2022
It was found that a specially crafted LUKS header could trick cryptsetup into disabling...
Moderate
Unreviewed
CVE-2021-4122
was published
Aug 25, 2022
Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal,...
High
Unreviewed
CVE-2020-12406
was published
May 24, 2022
OpenStack Compute (Nova) has Insufficient Verification of Data Authenticity
Moderate
CVE-2015-0259
was published
for
nova
(pip)
May 14, 2022
It was found that in icedtea-web up to and including 1.7.2 and 1.8.2 executable code could be...
High
Unreviewed
CVE-2019-10181
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API