GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
305,525 advisories
Filter by severity
If, after successful installation of MantisBT through 2.5.2 on MySQL/MariaDB, the administrator...
Moderate
Unreviewed
CVE-2017-12419
was published
May 17, 2022
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
High
Unreviewed
CVE-2017-12067
was published
May 17, 2022
A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an...
High
Unreviewed
CVE-2017-6746
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote...
Moderate
Unreviewed
CVE-2008-6876
was published
May 17, 2022
Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to...
Moderate
Unreviewed
CVE-2008-6840
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to...
Moderate
Unreviewed
CVE-2008-6838
was published
May 17, 2022
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE...
High
Unreviewed
CVE-2008-6962
was published
May 17, 2022
login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote...
Moderate
Unreviewed
CVE-2008-6896
was published
May 17, 2022
Multiple unspecified vulnerabilities in Sophos SAVScan 4.33.0 for Linux, and possibly other...
High
Unreviewed
CVE-2008-6904
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition...
Moderate
Unreviewed
CVE-2008-6894
was published
May 17, 2022
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on...
High
Unreviewed
CVE-2017-11742
was published
May 17, 2022
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of...
Critical
Unreviewed
CVE-2017-11673
was published
May 17, 2022
NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an...
High
Unreviewed
CVE-2017-6259
was published
May 17, 2022
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper...
Moderate
Unreviewed
CVE-2017-6260
was published
May 17, 2022
Services 5.x before 5.x-0.92 and 6.x before 6.x-0.13, a module for Drupal, does not use timeouts...
High
Unreviewed
CVE-2008-6910
was published
May 17, 2022
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote...
High
Unreviewed
CVE-2008-6887
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability in Vivvo CMS before 4.0.4 allows remote attackers...
Moderate
Unreviewed
CVE-2008-6801
was published
May 17, 2022
Directory traversal in convert-svg-core
High
CVE-2022-24278
was published
for
convert-svg-core
(npm)
Jun 11, 2022
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist...
High
Unreviewed
CVE-2022-29094
was published
Jun 11, 2022
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console...
Moderate
Unreviewed
CVE-2017-8000
was published
May 17, 2022
A vulnerability was found in SourceCodester Prison Management System 1.0. It has been rated as...
High
Unreviewed
CVE-2022-2017
was published
Jun 10, 2022
A vulnerability classified as critical has been found in SourceCodester Prison Management System...
High
Unreviewed
CVE-2022-2018
was published
Jun 10, 2022
Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an...
Moderate
Unreviewed
CVE-2022-29948
was published
Jun 11, 2022
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
Moderate
Unreviewed
CVE-2021-40610
was published
Jun 10, 2022
Server-Side Request Forgery in kityminder
Critical
CVE-2022-31830
was published
for
kityminder
(npm)
Jun 10, 2022
ProTip!
Advisories are also available from the
GraphQL API