GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,416
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
395 advisories
Filter by severity
PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x...
Moderate
Unreviewed
CVE-2014-8161
was published
May 17, 2022
Weblate user account enumeration via reset password form
Moderate
CVE-2017-5537
was published
for
weblate
(pip)
May 17, 2022
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks...
Critical
Unreviewed
CVE-2017-7551
was published
May 14, 2022
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers...
Moderate
Unreviewed
CVE-2013-7331
was published
May 14, 2022
Apache Ambari, version 2.5.0 to 2.6.2, passwords for Hadoop credential stores are exposed in...
High
Unreviewed
CVE-2018-8042
was published
May 13, 2022
In SAP HANA Extended Application Services, 1.0, an unauthenticated user could test if a given...
Moderate
Unreviewed
CVE-2018-2379
was published
May 13, 2022
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism...
High
Unreviewed
CVE-2018-17961
was published
May 13, 2022
Matera Banco 1.0.0 mishandles Java errors in the backend, as demonstrated by a stack trace...
Critical
Unreviewed
CVE-2018-14925
was published
May 13, 2022
An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill...
Critical
Unreviewed
CVE-2018-11325
was published
May 13, 2022
IBM Jazz Reporting Service (JRS) 5.0 and 6.0 could disclose sensitive information, including user...
Moderate
Unreviewed
CVE-2017-1370
was published
May 13, 2022
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a log pollution...
Moderate
Unreviewed
CVE-2016-9459
was published
May 13, 2022
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of...
Moderate
Unreviewed
CVE-2017-0885
was published
May 13, 2022
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3...
Moderate
Unreviewed
CVE-2018-10624
was published
May 13, 2022
katello SQL Injection vulnerability
Moderate
CVE-2018-14623
was published
for
katello
(RubyGems)
May 13, 2022
The GlobalProtect external interface in Palo Alto Networks PAN-OS before 6.1.17, 7.x before 7.0...
Critical
Unreviewed
CVE-2017-7945
was published
May 13, 2022
In JForum 2.1.8, an unauthenticated, remote attacker can enumerate whether a user exists by using...
Moderate
Unreviewed
CVE-2019-7550
was published
May 13, 2022
The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of...
Moderate
Unreviewed
CVE-2018-14907
was published
May 13, 2022
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP...
Moderate
Unreviewed
CVE-2010-3332
was published
May 13, 2022
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before...
High
Unreviewed
CVE-2019-9223
was published
May 13, 2022
IBM Guardium Data Encryption (GDE) 4.0.0 and 5.0.0 could allow a remote attacker to obtain...
High
Unreviewed
CVE-2021-39023
was published
May 7, 2022
When handling a mismatched pre-authentication cookie, the application leaks the internal error...
Moderate
Unreviewed
CVE-2022-26070
was published
May 7, 2022
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain...
Moderate
Unreviewed
CVE-2013-6879
was published
May 5, 2022
A server-generated error message containing sensitive information in Fortinet FortiOS 7.0.0...
Moderate
Unreviewed
CVE-2021-43206
was published
May 5, 2022
TYPO3 leaks a hash secret in an error message
Moderate
CVE-2009-0815
was published
for
typo3/cms
(Composer)
May 2, 2022
Apache Tomcat Leaks Information via Error Message
Moderate
CVE-2002-2008
was published
for
org.apache.tomcat:tomcat
(Maven)
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API