GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
418 advisories
Filter by severity
A flaw was found in RPM's signature check functionality when reading a package file. This flaw...
High
Unreviewed
CVE-2021-20271
was published
May 24, 2022
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior use a proprietary local area network ...
High
Unreviewed
CVE-2023-22315
was published
Jan 31, 2023
Lack of proper validation of server UUID can be used by the server to trick the client to accept invalid proofs
Moderate
CVE-2022-39199
was published
for
github.com/codenotary/immudb
(Go)
Nov 21, 2022
An exploitable code execution vulnerability exists in the Web-Based Management (WBM)...
High
Unreviewed
CVE-2020-6090
was published
May 24, 2022
Payment information sent to PayPal not necessarily identical to created order
High
CVE-2023-23941
was published
for
swag/paypal
(Composer)
Feb 3, 2023
A flaw was found in the Linux kernels SELinux LSM hook implementation before version 5.7, where...
Low
Unreviewed
CVE-2020-10751
was published
May 24, 2022
Insufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30...
Moderate
Unreviewed
CVE-2023-21441
was published
Feb 9, 2023
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file...
Moderate
Unreviewed
CVE-2019-12804
was published
May 24, 2022
Lack of root file system integrity checking in Fortinet FortiManager VM application images of all...
Critical
Unreviewed
CVE-2019-6695
was published
May 24, 2022
A vulnerability classified as critical has been found in Zerocoin libzerocoin. Affected is the...
High
Unreviewed
CVE-2017-20180
was published
Mar 6, 2023
Akuvox E11 does not ensure that a file extension is associated with the file provided. This could...
Moderate
Unreviewed
CVE-2023-0350
was published
Mar 13, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27979
was published
Mar 21, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27982
was published
Mar 21, 2023
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists in the Data Server...
High
Unreviewed
CVE-2023-27977
was published
Mar 21, 2023
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
High
Unreviewed
CVE-2023-26467
was published
Apr 11, 2023
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file...
Moderate
Unreviewed
CVE-2019-15613
was published
May 24, 2022
An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A...
Moderate
Unreviewed
CVE-2020-7982
was published
May 24, 2022
Auth0 Passport-SharePoint does not validate JWT signature
High
CVE-2019-13483
was published
for
passport-sharepoint
(npm)
May 24, 2022
A CWE-287: Improper Authentication vulnerability exists that could cause an attacker to...
Critical
Unreviewed
CVE-2022-0715
was published
Mar 10, 2022
Authentication Bypass by Spoofing and Insufficient Verification of Data Authenticity in Hashicorp Vault
High
CVE-2020-16250
was published
for
github.com/hashicorp/vault
(Go)
Aug 2, 2021
Token reuse in Ory fosite
High
CVE-2020-15222
was published
for
github.com/ory/fosite
(Go)
May 24, 2021
Prototype Pollution in defaults-deep
Critical
CVE-2018-16486
was published
for
defaults-deep
(npm)
Feb 7, 2019
Electron vulnerable to URL spoofing via PDFium
Moderate
CVE-2017-1000424
was published
for
Electron
(npm)
May 13, 2022
A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This...
Low
Unreviewed
CVE-2023-4177
was published
Aug 6, 2023
Insufficient Verification of Data Authenticity in Apache InLong
Moderate
CVE-2023-43666
was published
for
org.apache.inlong:inlong
(Maven)
Oct 16, 2023
ProTip!
Advisories are also available from the
GraphQL API