GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,100
Maven
5,000+
npm
3,764
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
177 advisories
Filter by severity
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same...
Moderate
Unreviewed
CVE-2019-14891
was published
May 24, 2022
IrfanView 4.53 allows a Exception Handler Chain to be Corrupted starting at EXR!ReadEXR...
Moderate
Unreviewed
CVE-2019-17257
was published
May 24, 2022
A CWE-754 Improper Check for Unusual or Exceptional Conditions vulnerability exists in Triconex...
Moderate
Unreviewed
CVE-2018-7803
was published
May 24, 2022
A vulnerability in the Border Gateway Patrol (BGP) Multiprotocol Label Switching (MPLS)-based...
Moderate
Unreviewed
CVE-2019-1849
was published
May 24, 2022
** DISPUTED ** An issue was discovered in ide_dma_cb() in hw/ide/core.c in QEMU 2.4.0 through 4.2...
Moderate
Unreviewed
CVE-2019-20175
was published
May 24, 2022
BuildKit vulnerable to possible panic when incorrect parameters sent from frontend
Moderate
CVE-2024-23650
was published
for
github.com/moby/buildkit
(Go)
Jan 31, 2024
A vulnerability in the interaction of SIP and Snort 3 for Cisco Firepower Threat Defense (FTD)...
Moderate
Unreviewed
CVE-2022-20950
was published
Nov 16, 2022
Vulnerability of improper checking for unusual or exceptional conditions
in Lamassu Bitcoin ATM...
Moderate
Unreviewed
CVE-2024-0675
was published
Jan 30, 2024
A user authorized to perform database queries may trigger denial of service by issuing specially...
Moderate
Unreviewed
CVE-2019-20924
was published
May 24, 2022
The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2023-6742
was published
Jan 11, 2024
An Improper Check for Unusual or Exceptional Conditions vulnerability in the kernel of Juniper...
Moderate
Unreviewed
CVE-2024-21603
was published
Jan 12, 2024
An elevation of privilege vulnerability exists when the Windows Language Pack Installer...
Moderate
Unreviewed
CVE-2020-1122
was published
May 24, 2022
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). Affected...
Moderate
Unreviewed
CVE-2023-48431
was published
Dec 12, 2023
Mattermost fails to validate the type of the "reminder" body request parameter allowing an...
Moderate
Unreviewed
CVE-2023-49607
was published
Dec 12, 2023
Uncaught exception for some Intel Unison software may allow an authenticated user to potentially...
Moderate
Unreviewed
CVE-2023-22290
was published
Nov 14, 2023
Improper conditions check in Zoom Team Chat for Zoom clients may allow an authenticated user to...
Moderate
Unreviewed
CVE-2023-39205
was published
Nov 15, 2023
Shopware improper mail validation vulnerability
Moderate
CVE-2023-34099
was published
for
shopware/shopware
(Composer)
Jun 28, 2023
Mattermost denial of service vulnerability
Moderate
CVE-2023-5967
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Nov 6, 2023
Electron context isolation bypass via nested unserializable return value
Moderate
CVE-2023-29198
was published
for
electron
(npm)
Sep 6, 2023
ink! vulnerable to incorrect decoding of storage value when using `DelegateCall`
Moderate
CVE-2023-34449
was published
for
ink
(Rust)
Jun 14, 2023
OctoRPKI crashes when max iterations is reached
Moderate
CVE-2022-3616
was published
for
github.com/cloudflare/cfrpki
(Go)
Oct 31, 2022
DoS attack can be performed when an email contains specially designed URL in the body. It can...
Moderate
Unreviewed
CVE-2021-21439
was published
May 24, 2022
IPFS go-bitfield vulnerable to DoS via malformed size arguments
Moderate
CVE-2023-23626
was published
for
github.com/ipfs/go-bitfield
(Go)
Feb 10, 2023
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37...
Moderate
Unreviewed
CVE-2021-44856
was published
Dec 26, 2022
Unauthorized property update in CheckboxGroup component in Vaadin 12-14 and 15-20
Moderate
CVE-2021-33605
was published
for
com.vaadin:vaadin-checkbox-flow
(Maven)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API