GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
50 advisories
Filter by severity
A minor information leak when running Screen with setuid-root privileges allosw unprivileged...
Low
Unreviewed
CVE-2025-46804
was published
May 26, 2025
HCL MyXalytics is affected by username enumeration vulnerability. This allows a malicious user...
Low
Unreviewed
CVE-2024-42174
was published
Jan 11, 2025
iptables-save in iptables before 1.2.4 records the "--reject-with icmp-host-prohibited" rule as "...
Low
Unreviewed
CVE-2001-1387
was published
Apr 30, 2022
IBM Common Cryptographic Architecture 7.0.0 through 7.5.51
could allow an attacker to obtain...
Low
Unreviewed
CVE-2024-41760
was published
Mar 11, 2025
Some Honor products are affected by incorrect privilege assignment vulnerability, successful...
Low
Unreviewed
CVE-2024-47149
was published
Dec 26, 2024
Some Honor products are affected by information leak vulnerability, successful exploitation could...
Low
Unreviewed
CVE-2024-47150
was published
Dec 26, 2024
Some Honor products are affected by information leak vulnerability, successful exploitation could...
Low
Unreviewed
CVE-2024-47156
was published
Dec 26, 2024
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden...
Low
Unreviewed
CVE-2023-36325
was published
Oct 9, 2024
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are...
Low
Unreviewed
CVE-2024-21251
was published
Oct 15, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21208
was published
Oct 15, 2024
Vulnerability in Oracle Java SE (component: Hotspot). Supported versions that are affected are...
Low
Unreviewed
CVE-2024-21210
was published
Oct 15, 2024
This issue was addressed by restricting options offered on a locked device. This issue is fixed...
Low
Unreviewed
CVE-2022-46724
was published
Aug 15, 2023
IBM Db2 for i 7.2, 7.3, 7.4, and 7.5 supplies user defined table function is vulnerable to user...
Low
Unreviewed
CVE-2024-31870
was published
Jun 15, 2024
** DISPUTED ** On ShapeShift KeepKey devices, a side channel for the row-based OLED display was...
Low
Unreviewed
CVE-2019-14355
was published
May 24, 2022
** DISPUTED ** On BC Vault devices, a side channel for the row-based SSD1309 OLED display was...
Low
Unreviewed
CVE-2019-14359
was published
May 24, 2022
** DISPUTED ** On Mooltipass Mini devices, a side channel for the row-based OLED display was...
Low
Unreviewed
CVE-2019-14357
was published
May 24, 2022
In placeCall of TelecomManager.java, there is a possible way to determine whether an app is...
Low
Unreviewed
CVE-2022-20531
was published
Dec 20, 2022
An information disclosure vulnerability exists on ARM implementations that use speculative...
Low
Unreviewed
CVE-2020-1459
was published
May 24, 2022
In Package Manager, there is a possible way to determine whether an app is installed, without...
Low
Unreviewed
CVE-2023-21349
was published
Oct 30, 2023
In Window Manager, there is a possible way to determine whether an app is installed, without...
Low
Unreviewed
CVE-2023-21348
was published
Oct 30, 2023
In Game Manager Service, there is a possible way to determine whether an app is installed,...
Low
Unreviewed
CVE-2023-21345
was published
Oct 30, 2023
In the Device Idle Controller, there is a possible way to determine whether an app is installed,...
Low
Unreviewed
CVE-2023-21346
was published
Oct 30, 2023
lxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer...
Low
Unreviewed
CVE-2022-47952
was published
Jan 1, 2023
In LocaleManager, there is a possible way to determine whether an app is installed, without query...
Low
Unreviewed
CVE-2022-20249
was published
Aug 12, 2022
In LocaleManager, there is a possible way to determine whether an app is installed, without query...
Low
Unreviewed
CVE-2022-20251
was published
Aug 12, 2022
ProTip!
Advisories are also available from the
GraphQL API