GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
39 advisories
Filter by severity
A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive...
Moderate
Unreviewed
CVE-2026-3833
was published
Apr 30, 2026
Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose...
High
Unreviewed
CVE-2026-62230
was published
Jul 17, 2026
A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.30. Affected...
Low
Unreviewed
CVE-2026-14617
was published
Jul 4, 2026
A flaw was found in libsoup. When handling cookies, libsoup clients mistakenly allow cookies to...
Moderate
Unreviewed
CVE-2025-4035
was published
Apr 29, 2025
Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a...
Low
Unreviewed
CVE-2026-58057
was published
Jun 28, 2026
An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6.
`django.middleware...
Low
Unreviewed
CVE-2026-8404
was published
Jun 3, 2026
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back...
Moderate
Unreviewed
CVE-2023-46218
was published
Dec 7, 2023
prompts.chat prior to commit 1464475 contains an identity confusion vulnerability due to...
High
Unreviewed
CVE-2026-22665
was published
Apr 3, 2026
Improper Handling of Case Sensitivity vulnerability in Drupal OpenID Connect / OAuth client...
Moderate
Unreviewed
CVE-2026-3532
was published
Mar 26, 2026
Mbedthis AppWeb HTTP server before 1.1.3 allows remote attackers to bypass access restrictions...
High
Unreviewed
CVE-2004-2214
was published
Apr 29, 2022
CUPS before 1.1.21rc1 treats a Location directive in cupsd.conf as case sensitive, which allows...
High
Unreviewed
CVE-2004-2154
was published
Apr 29, 2022
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a...
High
Unreviewed
CVE-2002-1820
was published
Apr 30, 2022
Apache for Apple Mac OS X 10.2.8 and 10.3.6 restricts access to files in a case sensitive manner,...
Moderate
Unreviewed
CVE-2004-1083
was published
Apr 29, 2022
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and...
High
Unreviewed
CVE-2020-12812
was published
May 24, 2022
In OpenEMR, versions v2.7.2-rc1 to 6.0.0 are vulnerable to Improper Access Control when creating...
Moderate
Unreviewed
CVE-2021-25920
was published
May 24, 2022
In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not...
Critical
Unreviewed
CVE-2024-5699
was published
Jun 11, 2024
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows...
Critical
Unreviewed
CVE-2022-29604
was published
Apr 20, 2023
Novell eDirectory 8.6.2 and 8.7 use case insensitive passwords, which makes it easier for remote...
High
Unreviewed
CVE-2002-2119
was published
Apr 30, 2022
The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all...
High
Unreviewed
CVE-2005-0269
was published
May 1, 2022
Sun ONE Application Server 7.0 for Windows 2000/XP allows remote attackers to obtain JSP source...
Moderate
Unreviewed
CVE-2003-0411
was published
Apr 29, 2022
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass...
High
Unreviewed
CVE-2001-0766
was published
Apr 30, 2022
Perception LiteServe 1.25 allows remote attackers to obtain source code of CGI scripts via URLs...
Moderate
Unreviewed
CVE-2001-0795
was published
Apr 30, 2022
MyServer 0.8.9 and earlier does not properly handle uppercase characters in filename extensions,...
High
Unreviewed
CVE-2007-3365
was published
May 1, 2022
IBM WebSphere server 3.0.2 allows a remote attacker to view source code of a JSP program by...
Moderate
Unreviewed
CVE-2000-0497
was published
Apr 30, 2022
Norton Anti-Virus (NAV) allows remote attackers to bypass content filtering via attachments whose...
Moderate
Unreviewed
CVE-2002-0485
was published
Apr 30, 2022
ProTip!
Advisories are also available from the
GraphQL API