GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,640
Maven
5,000+
npm
4,265
NuGet
760
pip
4,061
Pub
12
RubyGems
956
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
301,731 advisories
Filter by severity
Improper input validation check logic vulnerability in libsmkvextractor prior to SMR Jun-2022...
Moderate
Unreviewed
CVE-2022-30719
was published
Jun 8, 2022
Implicit Intent hijacking vulnerability in Samsung Account prior to SMR Jun-2022 Release 1 allows...
Critical
Unreviewed
CVE-2022-30722
was published
Jun 8, 2022
A Cross Site Scripting vulnerabilty exists in PartKeepr 1.4.0 via the 'name' field in /api...
Moderate
Unreviewed
CVE-2022-30899
was published
Jun 9, 2022
The Filr WordPress plugin before 1.2.2.1 does not have authorisation check in two of its AJAX...
High
Unreviewed
CVE-2022-1777
was published
Jun 14, 2022
Jettison parser crash by stackoverflow
Moderate
CVE-2022-40149
was published
for
org.codehaus.jettison:jettison
(Maven)
Sep 17, 2022
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the...
Critical
Unreviewed
CVE-2022-2336
was published
Aug 18, 2022
PNGDec commit 8abf6be was discovered to contain a stack overflow via /linux/main.cpp.
Moderate
Unreviewed
CVE-2022-35008
was published
Aug 17, 2022
PNGDec commit 8abf6be was discovered to contain a heap buffer overflow via __interceptor_fwrite...
Moderate
Unreviewed
CVE-2022-35007
was published
Aug 17, 2022
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[...
Moderate
Unreviewed
CVE-2022-1756
was published
Jun 14, 2022
Improper privilege management vulnerability in Samsung Account prior to 13.2.00.6 allows...
Moderate
Unreviewed
CVE-2022-30739
was published
Jun 8, 2022
HyperSQL DataBase vulnerable to remote code execution when processing untrusted input
Critical
CVE-2022-41853
was published
for
org.hsqldb:hsqldb
(Maven)
Oct 6, 2022
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a...
Critical
Unreviewed
CVE-2022-30877
was published
Jun 9, 2022
Apache Helix UI vulnerable to Open Redirect
Moderate
CVE-2022-47500
was published
for
org.apache.helix:helix
(Maven)
Dec 19, 2022
Agentflow BPM file download function has a path traversal vulnerability. An unauthenticated...
High
Unreviewed
CVE-2022-39037
was published
Nov 10, 2022
Cross-site Scripting in Dolibarr
Moderate
CVE-2022-30875
was published
for
dolibarr/dolibarr
(Composer)
Jun 9, 2022
Multiple directory traversal vulnerabilities in phpCDB 1.0 and earlier allow remote attackers to...
High
Unreviewed
CVE-2010-1537
was published
May 17, 2022
SQL injection vulnerability in the JoltCard (com_joltcard) component 1.2.1 for Joomla! allows...
High
Unreviewed
CVE-2010-1496
was published
May 17, 2022
PHP remote file inclusion vulnerability in eva/index.php in EVA CMS 2.3.1, when register_globals...
Moderate
Unreviewed
CVE-2008-7183
was published
May 17, 2022
SQL injection vulnerability in print_raincheck.php in phpRAINCHECK 1.0.1 and earlier allows...
High
Unreviewed
CVE-2010-1538
was published
May 17, 2022
Multiple unspecified vulnerabilities in Shareaza before 2.3.1.0 have unknown impact and attack...
High
Unreviewed
CVE-2008-7164
was published
May 17, 2022
A vulnerability was found in OSM Lab show-me-the-way. It has been rated as problematic. This...
Moderate
Unreviewed
CVE-2018-25064
was published
Jan 5, 2023
Mail in Apple iOS before 10 mishandles certificates, which makes it easier for man-in-the-middle...
Moderate
Unreviewed
CVE-2016-4747
was published
May 17, 2022
The Sandbox Profiles component in Apple iOS before 10 does not properly restrict access to...
Moderate
Unreviewed
CVE-2016-4620
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in Blink, as used in Google Chrome before 53.0.2785.89...
Moderate
Unreviewed
CVE-2016-5148
was published
May 17, 2022
The Assets component in Apple iOS before 10 allows man-in-the-middle attackers to block software...
Moderate
Unreviewed
CVE-2016-4741
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API