GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
AMD microprocessor families 15h to 18h are affected by a new Spectre variant that is able to...
Moderate
Unreviewed
CVE-2022-29900
was published
Jul 13, 2022
Protected fields exposed via LiveQuery
High
CVE-2022-31112
was published
for
parse-server
(npm)
Jul 6, 2022
CURLOPT_HTTPAUTH option not cleared on change of origin
High
CVE-2022-31090
was published
for
guzzlehttp/guzzle
(Composer)
Jun 21, 2022
Vulnerability of residual files not being deleted after an update in the ChinaDRM module....
High
Unreviewed
CVE-2021-46813
was published
Jun 14, 2022
Failure to strip the Cookie header on change in host or HTTP downgrade
High
CVE-2022-31042
was published
for
guzzlehttp/guzzle
(Composer)
Jun 9, 2022
Fix failure to strip Authorization header on HTTP downgrade
High
CVE-2022-31043
was published
for
guzzlehttp/guzzle
(Composer)
Jun 9, 2022
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository polonel/trudesk...
Moderate
Unreviewed
CVE-2022-1893
was published
Jun 1, 2022
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS)....
High
Unreviewed
CVE-2020-36476
was published
May 24, 2022
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP...
High
Unreviewed
CVE-2020-14301
was published
May 24, 2022
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to...
High
Unreviewed
CVE-2021-31780
was published
May 24, 2022
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information...
High
Unreviewed
CVE-2021-0340
was published
May 24, 2022
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000...
Moderate
Unreviewed
CVE-2021-3031
was published
May 24, 2022
Some websites have a feature "Show Password" where clicking a button will change a password field...
Moderate
Unreviewed
CVE-2020-26965
was published
May 24, 2022
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors...
Moderate
Unreviewed
CVE-2020-8696
was published
May 24, 2022
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for...
Low
Unreviewed
CVE-2020-13179
was published
May 24, 2022
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without...
Low
Unreviewed
CVE-2020-11740
was published
May 24, 2022
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3...
Moderate
Unreviewed
CVE-2019-20637
was published
May 24, 2022
An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730...
Moderate
Unreviewed
CVE-2019-19362
was published
May 24, 2022
Kubernetes did not effectively clear service account credentials
High
CVE-2019-11243
was published
for
k8s.io/kubernetes
(Go)
May 24, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
High
CVE-2022-30617
was published
for
@strapi/strapi
(npm)
May 20, 2022
Improper Removal of Sensitive Information Before Storage or Transfer in Strapi
High
CVE-2022-30618
was published
for
@strapi/strapi
(npm)
May 20, 2022
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called...
High
Unreviewed
CVE-2018-6337
was published
May 13, 2022
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable...
Moderate
Unreviewed
CVE-2018-1062
was published
May 13, 2022
Exposure of Sensitive Information in eventsource
Critical
CVE-2022-1650
was published
for
eventsource
(npm)
May 13, 2022
Exposure of sensitive system information due to uncleared debug information in firmware for some...
Moderate
Unreviewed
CVE-2021-33080
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API