GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,437 advisories
Filter by severity
MapProxy vulnerable to cross-site scripting in demo service
Moderate
CVE-2017-1000426
was published
for
MapProxy
(pip)
May 13, 2022
Withdrawn Advisory: Pulp Improper Path Parsing
Moderate
CVE-2018-10917
was published
for
pulpcore
(pip)
May 13, 2022
•
withdrawn
OpenStack Nova Filter Scheduler Bypass
Moderate
CVE-2017-16239
was published
for
nova
(pip)
May 13, 2022
Openstack tripleo-heat-templates unauthenticated file access
Moderate
CVE-2017-12155
was published
for
tripleo-heat-templates
(pip)
May 13, 2022
Tryton Information Disclosure Vulnerability
Moderate
CVE-2017-0360
was published
for
trytond
(pip)
May 13, 2022
Bodhi Cross-site Scripting Vulnerability
Moderate
CVE-2017-1002152
was published
for
bodhi
(pip)
May 13, 2022
Openstack Neutron vulnerable to eavesdropping on private traffic
Moderate
CVE-2018-14636
was published
for
neutron
(pip)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in IPython
Moderate
CVE-2015-4707
was published
for
ipython
(pip)
May 13, 2022
sosreport sensitive information disclosure via weak permissions of the generated archives
Moderate
CVE-2015-3171
was published
for
sosreport
(pip)
May 13, 2022
SleekXMPP and Slixmpp Incorrect Implementation of Message Carbons
Moderate
CVE-2017-5591
was published
for
SleekXMPP
(pip)
May 13, 2022
Kallithea cross-site scripting (XSS) vulnerability
Moderate
CVE-2015-1864
was published
for
Kallithea
(pip)
May 13, 2022
OpenStack Identity Keystone Exposure of Sensitive Information
Moderate
CVE-2014-3621
was published
for
keystone
(pip)
May 13, 2022
OpenStack Identity Keystone Improper Privilege Management
Moderate
CVE-2014-0204
was published
for
keystone
(pip)
May 13, 2022
OpenStack Keystone Logs Passwords
Moderate
CVE-2015-3646
was published
for
keystone
(pip)
May 13, 2022
OpenStack Identity Keystone is vulnerable to Block delegation escalation of privilege
Moderate
CVE-2014-3476
was published
for
keystone
(pip)
May 13, 2022
OpenStack Identity (Keystone) Denial of Service
Moderate
CVE-2013-2014
was published
for
keystone
(pip)
May 13, 2022
SaltStack Salt Directory Traversal vulnerability in salt-api
Moderate
CVE-2018-15750
was published
for
salt
(pip)
May 13, 2022
Ceilometer Prints Sensitive Configuration Data to Log
Moderate
CVE-2019-3830
was published
for
ceilometer
(pip)
May 13, 2022
Improper Neutralization of Input During Web Page Generation in LXML
Moderate
CVE-2018-19787
was published
for
lxml
(pip)
May 13, 2022
Horizon-Orchestration Cross-site scripting (XSS) vulnerability through resource name
Moderate
CVE-2014-3473
was published
for
horizon
(pip)
May 13, 2022
Improper Link Resolution Before File Access in pip
Moderate
CVE-2013-1888
was published
for
pip
(pip)
May 13, 2022
pip lack of randomness in build directory
Moderate
CVE-2014-8991
was published
for
pip
(pip)
May 13, 2022
Python Requests Session Fixation
Moderate
CVE-2015-2296
was published
for
requests
(pip)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API