GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
249 advisories
Filter by severity
Mercurial vulnerable to arbitrary code execution via a crafted name when converting a Git repository
High
CVE-2016-3069
was published
for
mercurial
(pip)
May 14, 2022
Mercurial arbitrary code execution via a crafted git ext:: URL
High
CVE-2016-3068
was published
for
mercurial
(pip)
May 14, 2022
Mercurial vulnerable to arbitrary command execution via a crafted repository name in a clone command
Critical
CVE-2014-9462
was published
for
mercurial
(pip)
May 14, 2022
Pillow denial of service via PNG bomb
High
CVE-2014-9601
was published
for
pillow
(pip)
May 14, 2022
Pillow denial of service via Crafted Block Size
High
CVE-2014-3589
was published
for
pillow
(pip)
May 14, 2022
httplib2 incorrectly checks SSL certificate
Moderate
CVE-2013-2037
was published
for
httplib2
(pip)
May 14, 2022
Withdrawn Advisory: OnionShare Predictable Pathname
High
CVE-2018-19960
was published
for
onionshare-cli
(pip)
May 14, 2022
•
withdrawn
Python RSA allows attackers to spoof signatures
Moderate
CVE-2016-1494
was published
for
rsa
(pip)
May 14, 2022
OpenStack Identity (Keystone) Denial of Service
Moderate
CVE-2013-2014
was published
for
keystone
(pip)
May 13, 2022
Mercurial Improper Input Validation vulnerability
High
CVE-2018-13348
was published
for
mercurial
(pip)
May 13, 2022
Mercurial Improper Input Validation vulnerability
High
CVE-2018-13346
was published
for
mercurial
(pip)
May 13, 2022
Apache Qpid Python client Improper certificate validation
High
CVE-2013-1909
was published
for
qpid-python
(pip)
May 13, 2022
Ansible Improper Input Validation vulnerability
High
CVE-2018-10874
was published
for
ansible
(pip)
May 13, 2022
OpensStack Neutron Denial of Service Vulnerability
High
CVE-2018-14635
was published
for
neutron
(pip)
May 13, 2022
Tenant and Verifier might not use the same registrar data
Critical
CVE-2022-1053
was published
for
keylime
(pip)
May 5, 2022
ReviewBoard and Djblets library are vulnerable to code execution
Critical
CVE-2013-4409
was published
for
ReviewBoard
(pip)
May 5, 2022
Improper Input Validation in pyftpdlib
High
CVE-2007-6739
was published
for
pyftpdlib
(pip)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API