GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,091 advisories
Filter by severity
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2018-19881
was published
May 14, 2022
In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36...
High
Unreviewed
CVE-2018-15607
was published
May 14, 2022
In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0...
High
Unreviewed
CVE-2018-8777
was published
May 14, 2022
In LibSass prior to 3.5.5, Sass::Eval::operator()(Sass::Binary_Expression*) inside eval.cpp...
Moderate
Unreviewed
CVE-2018-19837
was published
May 14, 2022
In LibSass prior to 3.5.5, functions inside ast.cpp for IMPLEMENT_AST_OPERATORS expansion allow...
Moderate
Unreviewed
CVE-2018-19838
was published
May 14, 2022
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An...
Moderate
Unreviewed
CVE-2018-1157
was published
May 14, 2022
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which...
Moderate
Unreviewed
CVE-2018-15853
was published
May 14, 2022
CiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption...
Moderate
Unreviewed
CVE-2018-17581
was published
May 14, 2022
An issue was discovered in the Linux kernel before 4.19.9. The USB subsystem mishandles size...
High
Unreviewed
CVE-2018-20169
was published
May 14, 2022
The iw_read_gif_file function in imagew-gif.c in libimageworsener.a in ImageWorsener 1.3.0 allows...
Moderate
Unreviewed
CVE-2017-7940
was published
May 13, 2022
** DISPUTED ** Header::readfrom in IlmImf/ImfHeader.cpp in OpenEXR 2.2.0 allows remote attackers...
Moderate
Unreviewed
CVE-2017-14988
was published
May 13, 2022
When there are multiple ranges in a range request, Apache Traffic Server (ATS) will read the...
Moderate
Unreviewed
CVE-2018-8005
was published
May 13, 2022
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a...
High
Unreviewed
CVE-2018-5954
was published
May 13, 2022
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10...
High
Unreviewed
CVE-2018-4100
was published
May 13, 2022
There is a stack consumption vulnerability in the res_http_websocket.so module of Asterisk...
High
Unreviewed
CVE-2018-17281
was published
May 13, 2022
** DISPUTED ** Technicolor TG588V V2 devices allow remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2018-16310
was published
May 13, 2022
** DISPUTED ** Technicolor TC7200.20 devices allow remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2018-15852
was published
May 13, 2022
** DISPUTED ** Technicolor (formerly RCA) TC8305C devices allow remote attackers to cause a...
Moderate
Unreviewed
CVE-2018-15907
was published
May 13, 2022
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large...
High
Unreviewed
CVE-2018-14940
was published
May 13, 2022
wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption...
High
Unreviewed
CVE-2018-14596
was published
May 13, 2022
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils...
Moderate
Unreviewed
CVE-2018-12641
was published
May 13, 2022
LogMeIn LastPass through 4.15.0 allows remote attackers to cause a denial of service (browser...
High
Unreviewed
CVE-2018-10193
was published
May 13, 2022
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to...
High
Unreviewed
CVE-2017-8338
was published
May 13, 2022
The bmpr_read_uncompressed function in imagew-bmp.c in libimageworsener.a in ImageWorsener before...
High
Unreviewed
CVE-2017-8327
was published
May 13, 2022
A userspace process can cause a Denial of Service in the camera driver in all Qualcomm products...
High
Unreviewed
CVE-2017-8264
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API