GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
3,036 advisories
Filter by severity
A locally locally exploitable DOS vulnerability was found in pax-linux versions 2.6.32.33-test79...
Moderate
Unreviewed
CVE-2011-1474
was published
Apr 22, 2022
A local file inclusion flaw was found in the way the phpLDAPadmin before 0.9.8 processed certain...
High
Unreviewed
CVE-2011-4082
was published
Apr 22, 2022
Denial of service in Spring Security OAuth2
Moderate
CVE-2022-22969
was published
for
org.springframework.security.oauth:spring-security-oauth2
(Maven)
Apr 22, 2022
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send...
High
Unreviewed
CVE-2002-20001
was published
Apr 21, 2022
The affected product is vulnerable to a network-based attack by threat actors sending unimpeded...
High
Unreviewed
CVE-2021-43933
was published
Apr 21, 2022
An issue was discovered in Asterisk through 19.x. When using STIR/SHAKEN, it is possible to...
High
Unreviewed
CVE-2022-26498
was published
Apr 16, 2022
A vulnerability in the NETCONF over SSH feature of Cisco IOS XE Software could allow a low...
Moderate
Unreviewed
CVE-2022-20692
was published
Apr 16, 2022
A Denial of Service (DoS) vulnerability in the processing of a flood of specific ARP traffic in...
Moderate
Unreviewed
CVE-2022-22191
was published
Apr 15, 2022
Resource exhaustion in Mattermost
Moderate
CVE-2022-1337
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Apr 14, 2022
A vulnerability has been identified in SIMATIC CFU DIQ (All versions), SIMATIC CFU PA (All...
High
Unreviewed
CVE-2022-25622
was published
Apr 13, 2022
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) (All versions <...
High
Unreviewed
CVE-2022-27194
was published
Apr 13, 2022
A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause...
High
Unreviewed
CVE-2022-21155
was published
Apr 13, 2022
Due to an uncontrolled recursion in SAP Web Dispatcher and SAP Internet Communication Manager,...
High
Unreviewed
CVE-2022-28773
was published
Apr 13, 2022
Denial of Service (DoS) in Nokogiri on JRuby
High
GHSA-gx8x-g87m-h5q6
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
Nokogiri Inefficient Regular Expression Complexity
High
CVE-2022-24836
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
Unsafe parsing in SWHKD
Moderate
CVE-2022-27819
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 8, 2022
Adding a very large number of tags to a runner in GitLab CE/EE affecting all versions prior to 14...
Moderate
Unreviewed
CVE-2022-1099
was published
Apr 5, 2022
A denial of service vulnerability when rendering RDoc files in GitLab CE/EE versions 10 to 14.7.7...
Moderate
Unreviewed
CVE-2022-1185
was published
Apr 5, 2022
A potential DoS vulnerability was discovered in Gitlab CE/EE versions 13.7 before 14.7.7, all...
High
Unreviewed
CVE-2022-1174
was published
Apr 5, 2022
A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this...
Moderate
Unreviewed
CVE-2022-1210
was published
Apr 4, 2022
Unauthenticated users can access sensitive web URLs through GET request, which should be...
Moderate
Unreviewed
CVE-2021-32503
was published
Apr 3, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was...
Moderate
Unreviewed
CVE-2022-0489
was published
Apr 3, 2022
Uncontrolled Resource Consumption in Matrix Synapse
Moderate
CVE-2022-41952
was published
for
matrix-synapse
(pip)
Apr 1, 2022
totolink EX300_v2, ver V4.0.3c.140_B20210429 and A720R ,ver V4.1.5cu.470_B20200911 have an issue...
Moderate
Unreviewed
CVE-2021-43662
was published
Apr 1, 2022
ProTip!
Advisories are also available from the
GraphQL API