GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
71 advisories
Filter by severity
RPyC's missing security check results in code execution when using numpy.array on the server-side.
High
CVE-2024-27758
was published
for
rpyc
(pip)
Mar 6, 2024
Java: DoS Vulnerability in JSON-JAVA
High
CVE-2023-5072
was published
for
org.json:json
(Maven)
Nov 14, 2023
vantage6-server node accepts non-whitelisted algorithms from malicious server
High
CVE-2023-47631
was published
for
vantage6-node
(pip)
Nov 14, 2023
The issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17...
High
Unreviewed
CVE-2023-40445
was published
Oct 25, 2023
A non-feature complete authentication mechanism exists in the production application allowing an...
Critical
Unreviewed
CVE-2023-3266
was published
Aug 14, 2023
Parameter verification vulnerability in the installd module. Successful exploitation of this...
Critical
Unreviewed
CVE-2023-39403
was published
Aug 13, 2023
Client Spoofing within the Keycloak Device Authorisation Grant
Low
CVE-2023-2585
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Jun 30, 2023
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the...
Moderate
Unreviewed
CVE-2023-28601
was published
Jun 13, 2023
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss...
Moderate
Unreviewed
CVE-2021-26328
was published
Jan 11, 2023
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive...
High
Unreviewed
CVE-2022-3691
was published
Nov 21, 2022
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which...
High
Unreviewed
CVE-2022-38732
was published
Sep 30, 2022
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address...
Moderate
Unreviewed
CVE-2021-34790
was published
May 24, 2022
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address...
Moderate
Unreviewed
CVE-2021-34791
was published
May 24, 2022
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in...
Moderate
Unreviewed
CVE-2020-10743
was published
May 24, 2022
A flaw was found in the OpenShift web console, where the access token is stored in the browser's...
Moderate
Unreviewed
CVE-2020-1761
was published
May 24, 2022
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for...
Moderate
Unreviewed
CVE-2021-3448
was published
May 24, 2022
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query,...
Moderate
Unreviewed
CVE-2020-25684
was published
May 24, 2022
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query,...
Moderate
Unreviewed
CVE-2020-25685
was published
May 24, 2022
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check...
Moderate
Unreviewed
CVE-2020-25686
was published
May 24, 2022
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager...
High
Unreviewed
CVE-2019-14823
was published
May 24, 2022
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned...
Moderate
Unreviewed
CVE-2018-20934
was published
May 24, 2022
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
High
Unreviewed
CVE-2016-10834
was published
May 24, 2022
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents...
High
Unreviewed
CVE-2016-10825
was published
May 24, 2022
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4...
High
Unreviewed
CVE-2018-16860
was published
May 24, 2022
Curam Universal Access in IBM Curam Social Program Management (SPM) 6.0 SP2 before EP26, 6.0.4...
Moderate
Unreviewed
CVE-2014-4843
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API