GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
75 advisories
Filter by severity
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations...
Critical
Unreviewed
CVE-2017-16597
was published
May 13, 2022
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations...
Critical
Unreviewed
CVE-2017-16610
was published
May 13, 2022
A vulnerability in the Traversal Using Relay NAT (TURN) server included with Cisco Meeting Server...
Critical
Unreviewed
CVE-2017-12249
was published
May 13, 2022
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Automobile and...
Critical
Unreviewed
CVE-2017-18129
was published
May 13, 2022
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices...
Critical
Unreviewed
CVE-2018-18068
was published
May 13, 2022
A remote bypass of security restrictions vulnerability was identified in HPE Moonshot...
Critical
Unreviewed
CVE-2018-7072
was published
May 13, 2022
The component /rootfs in RageFile of Stepmania v5.1b2 and below allows attackers access to the...
Critical
Unreviewed
CVE-2022-25010
was published
Mar 3, 2022
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the...
Critical
Unreviewed
CVE-2020-22647
was published
Mar 16, 2023
Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI-Generator online generator
Critical
CVE-2021-21428
was published
for
org.openapitools:openapi-generator-online
(Maven)
May 11, 2021
Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any...
Critical
Unreviewed
CVE-2022-24074
was published
Mar 18, 2022
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can...
Critical
Unreviewed
CVE-2022-21817
was published
Feb 8, 2022
Zoho ManageEngine PAM360 before build 5303 allows attackers to modify a few aspects of...
Critical
Unreviewed
CVE-2021-44525
was published
Dec 21, 2021
Zoho ManageEngine Access Manager Plus before 4203 allows anyone to view a few data elements (e.g....
Critical
Unreviewed
CVE-2021-44676
was published
Dec 21, 2021
globalpom-utils has Insecure Temporary File
Critical
CVE-2018-25068
was published
for
com.anrisoftware.globalpom:globalpomutils
(Maven)
Jan 6, 2023
seatd-launch in seatd 0.6.x before 0.6.4 allows removing files with escalated privileges when...
Critical
Unreviewed
CVE-2022-25643
was published
Feb 25, 2022
Exposure of sensitive information in Apache Ozone
Critical
CVE-2021-39231
was published
for
org.apache.ozone:ozone-main
(Maven)
Nov 23, 2021
Exposure of Resource to Wrong Sphere in Zip-Local
Critical
CVE-2021-23484
was published
for
zip-local
(npm)
Feb 1, 2022
CodenameOne Pending Intent vulnerability
Critical
CVE-2022-4903
was published
for
com.codenameone:codenameone-core
(Maven)
Feb 10, 2023
Mondo 2.24 has insecure handling of temporary files.
Critical
Unreviewed
CVE-2007-3915
was published
Apr 21, 2022
The QMP guest_exec command in QEMU 4.0.0 and earlier is prone to OS command injection, which...
Critical
Unreviewed
CVE-2019-12929
was published
May 24, 2022
** DISPUTED ** TensorFlow through 2.5.0 allows attackers to overwrite arbitrary files via a...
Critical
Unreviewed
CVE-2021-35958
was published
May 24, 2022
The QMP migrate command in QEMU version 4.0.0 and earlier is vulnerable to OS command injection,...
Critical
Unreviewed
CVE-2019-12928
was published
May 24, 2022
A vulnerability in Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated...
Critical
Unreviewed
CVE-2019-1848
was published
May 24, 2022
An issue was discovered in TitanHQ WebTitan before 5.18. The proxy service (which is typically...
Critical
Unreviewed
CVE-2019-19015
was published
May 24, 2022
Key management vulnerability on system. Successful exploitation of this vulnerability may affect...
Critical
Unreviewed
CVE-2023-3455
was published
Jul 5, 2023
ProTip!
Advisories are also available from the
GraphQL API