GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
371 advisories
Filter by severity
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL...
Low
Unreviewed
CVE-2023-41782
was published
Jan 5, 2024
A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS)...
Low
Unreviewed
CVE-2020-1455
was published
May 24, 2022
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to...
Low
Unreviewed
CVE-2020-0904
was published
May 24, 2022
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an...
Low
Unreviewed
CVE-2023-22329
was published
Nov 14, 2023
Jenkins Resource Disposer Plugin allows attacker to stop tracking specified resource
Low
CVE-2018-1999037
was published
for
org.jenkins-ci.plugins:resource-disposer
(Maven)
May 14, 2022
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000...
Low
Unreviewed
CVE-2023-22439
was published
Dec 19, 2023
Adobe Experience Manager versions 6.5.18 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2023-48608
was published
Dec 15, 2023
Improper input validation vulnerability in Newsletter Software SuperMailer affecting version 11...
Low
Unreviewed
CVE-2023-6381
was published
Dec 13, 2023
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to...
Low
Unreviewed
CVE-2023-5274
was published
Nov 30, 2023
Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to...
Low
Unreviewed
CVE-2023-5275
was published
Nov 30, 2023
Improper input validation for some Intel Unison software may allow an authenticated user to...
Low
Unreviewed
CVE-2022-45469
was published
Nov 14, 2023
Improper access control in Elenos ETG150 FM transmitter v3.12 allows attackers to make arbitrary...
Low
Unreviewed
CVE-2023-37833
was published
Nov 1, 2023
Silverstripe Framework: Members with no password can be created and bypass custom login forms
Low
CVE-2023-32302
was published
for
silverstripe/framework
(Composer)
Jul 31, 2023
Adobe Bridge version 11.0.2 (and earlier) is affected by an uninitialized variable vulnerability...
Low
Unreviewed
CVE-2021-35991
was published
May 24, 2022
Improper Sanitizing of plugin names in helm
Low
CVE-2020-15186
was published
for
helm.sh/helm
(Go)
May 24, 2021
Panic due to malformed WALs in go.etcd.io/etcd
Low
CVE-2020-15106
was published
for
go.etcd.io/etcd
(Go)
Feb 7, 2023
Repository index file allows for duplicates of the same chart entry in helm
Low
CVE-2020-15185
was published
for
helm.sh/helm
(Go)
May 24, 2021
Aliases are never checked in helm
Low
CVE-2020-15184
was published
for
helm.sh/helm
(Go)
May 24, 2021
Phusion Passenger allows remote attackers to spoof headers
Low
CVE-2015-7519
was published
for
passenger
(RubyGems)
Oct 10, 2018
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users...
Low
Unreviewed
CVE-2019-2389
was published
May 24, 2022
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65...
Low
Unreviewed
CVE-2019-0094
was published
May 24, 2022
Lack of adequate input/output validation for ABB eSOMS versions 4.0 to 6.0.2 might allow an...
Low
Unreviewed
CVE-2019-19095
was published
May 24, 2022
In Core Utilities, there is a possible way to craft a malformed Uri object due to improper input...
Low
Unreviewed
CVE-2022-20338
was published
Aug 13, 2022
In onCreatePreferences of EditInfoFragment.java, there is a possible way to read contacts...
Low
Unreviewed
CVE-2023-20932
was published
Feb 28, 2023
Improper input validation vulnerability in TelephonyUI prior to SMR Jan-2023 Release 1 allows...
Low
Unreviewed
CVE-2023-21428
was published
Feb 9, 2023
ProTip!
Advisories are also available from the
GraphQL API