GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
229 advisories
Filter by severity
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows...
Critical
Unreviewed
CVE-2024-4008
was published
Jun 5, 2024
E-WEBInformationCo. FS-EZViewer(Web) exposes sensitive information in the service. A remote...
Critical
Unreviewed
CVE-2024-4300
was published
Apr 29, 2024
An exposure of sensitive information vulnerability has been reported to affect Media Streaming...
Critical
Unreviewed
CVE-2023-47222
was published
Apr 26, 2024
Credential leak in org.apache.directory.api:apache-ldap-api
Critical
CVE-2018-1337
was published
for
org.apache.directory.api:apache-ldap-api
(Maven)
Nov 9, 2018
By knowing an organization's ID, an attacker can join the organization without permission and...
Critical
Unreviewed
CVE-2024-1643
was published
Apr 10, 2024
When doing HTTP(S) transfers, libcurl might erroneously use the read callback (...
Critical
Unreviewed
CVE-2022-32221
was published
Dec 6, 2022
The Migration, Backup, Staging - WPvivid plugin for WordPress is vulnerable to Sensitive...
Critical
Unreviewed
CVE-2023-5576
was published
Oct 20, 2023
Advantech R-SeeNet v2.4.23 allows an unauthenticated remote attacker to read from and write to...
Critical
Unreviewed
CVE-2023-5642
was published
Oct 18, 2023
Version 10.11 of webMethods OneData runs an embedded instance of Azul Zulu Java 11.0.15 which...
Critical
Unreviewed
CVE-2023-0925
was published
Sep 6, 2023
An attacker with basic privileges in SAP BusinessObjects Business Intelligence Platform ...
Critical
Unreviewed
CVE-2023-28765
was published
Jul 6, 2023
Input verification vulnerability in the AMS module. Successful exploitation of this vulnerability...
Critical
Unreviewed
CVE-2022-48510
was published
Jul 6, 2023
Key management vulnerability on system. Successful exploitation of this vulnerability may affect...
Critical
Unreviewed
CVE-2023-3455
was published
Jul 5, 2023
Vulnerability of incomplete read and write permission verification in the GPU module. Successful...
Critical
Unreviewed
CVE-2021-46891
was published
Jul 5, 2023
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM...
Critical
Unreviewed
CVE-2023-32113
was published
May 9, 2023
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a...
Critical
Unreviewed
CVE-2019-15859
was published
May 24, 2022
HPE has identified a vulnerability in HPE 3PAR Service Processor (SP) version 4.1 through 4.4....
Critical
Unreviewed
CVE-2019-11991
was published
May 24, 2022
systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext...
Critical
Unreviewed
CVE-2018-20839
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** Emerson Dixell XWEB-500 products are affected by arbitrary file...
Critical
Unreviewed
CVE-2021-45420
was published
Feb 15, 2022
As a default user on a multi-user instance of AnythingLLM, you could execute a call to the `...
Critical
Unreviewed
CVE-2024-0765
was published
Mar 3, 2024
Gradio Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Critical
CVE-2023-6572
was published
for
gradio
(pip)
Dec 14, 2023
IcedTea6 before 1.7.4 allow unsigned apps to read and write arbitrary files, related to Extended...
Critical
Unreviewed
CVE-2010-2783
was published
Apr 21, 2022
Potential Remote Code Execution in TYPO3 with mediace extension
Critical
CVE-2020-15086
was published
for
friendsoftypo3/mediace
(Composer)
Jul 29, 2020
Cache poisoning in drupal/core
Critical
CVE-2023-5256
was published
for
drupal/core
(Composer)
Sep 28, 2023
Openstack Magnum Unsafe Credential Handling
Critical
CVE-2016-7404
was published
for
openstack-magnum
(pip)
May 24, 2022
Exposure of Sensitive Information in eventsource
Critical
CVE-2022-1650
was published
for
eventsource
(npm)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API