GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
613 advisories
Filter by severity
In ContentService, there is a possible way to read installed sync content providers due to side...
Moderate
Unreviewed
CVE-2023-21306
was published
Oct 30, 2023
In Overlay Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21330
was published
Oct 30, 2023
In Content, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21316
was published
Oct 30, 2023
In PackageManager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21300
was published
Oct 30, 2023
In Activity Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21323
was published
Oct 30, 2023
In Package Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21299
was published
Oct 30, 2023
In Package Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21302
was published
Oct 30, 2023
In Settings, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21325
was published
Oct 30, 2023
In ContentService, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21317
was published
Oct 30, 2023
In Package Manager Service, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2023-21326
was published
Oct 30, 2023
In PackageManagerNative, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2023-21293
was published
Oct 30, 2023
In ActivityManagerService, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2023-21301
was published
Oct 30, 2023
In Content Service, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21304
was published
Oct 30, 2023
In Content, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21305
was published
Oct 30, 2023
In UsageStatsService, there is a possible way to read installed 3rd party apps due to side...
Moderate
Unreviewed
CVE-2023-21319
was published
Oct 30, 2023
In Device Policy, there is a possible way to verify if a particular admin app is registered on...
Moderate
Unreviewed
CVE-2023-21320
was published
Oct 30, 2023
Using iterative requests an attacker was able to learn the size of an opaque response, as well as...
Moderate
Unreviewed
CVE-2023-5722
was published
Oct 25, 2023
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM,...
Moderate
Unreviewed
CVE-2022-25332
was published
Oct 19, 2023
User enumeration is found in in PHPJabbers Appointment Scheduler 3.0. This issue occurs during...
High
Unreviewed
CVE-2023-36127
was published
Oct 11, 2023
A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All...
Moderate
Unreviewed
CVE-2023-43623
was published
Oct 10, 2023
Economizzer user enumeration vulnerability
Moderate
CVE-2023-38871
was published
for
gugoan/economizzer
(Composer)
Sep 28, 2023
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software...
Moderate
Unreviewed
CVE-2023-44216
was published
Sep 27, 2023
NVIDIA DGX H100 BMC contains a vulnerability in the host KVM daemon, where an unauthenticated...
High
Unreviewed
CVE-2023-25529
was published
Sep 20, 2023
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this...
Moderate
Unreviewed
CVE-2023-4095
was published
Sep 19, 2023
Piccolo's current `BaseUser.login` implementation is vulnerable to time based user enumeration
Moderate
CVE-2023-41885
was published
for
piccolo
(pip)
Sep 12, 2023
ProTip!
Advisories are also available from the
GraphQL API