GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,577 advisories
Filter by severity
The Zone Controller service in the Zoom On-Premise Meeting Connector Controller before version 4...
High
Unreviewed
CVE-2021-34415
was published
May 24, 2022
In onCreate of ConfirmConnectActivity, there is a possible remote bypass of user consent due to...
High
Unreviewed
CVE-2021-0594
was published
May 24, 2022
In ellipsize of Layout.java, there is a possible ANR due to improper input validation. This could...
Moderate
Unreviewed
CVE-2021-0687
was published
May 24, 2022
Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left...
Moderate
Unreviewed
CVE-2016-5267
was published
May 17, 2022
IBM API Connect 5.0.0.0 through 5.0.8.10 is vulnerable to HTTP header injection, caused by...
Moderate
Unreviewed
CVE-2020-4706
was published
May 24, 2022
QuickerSite 1.8.5 allows remote attackers to obtain sensitive information via a request to...
Moderate
Unreviewed
CVE-2008-6676
was published
May 17, 2022
Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows...
Critical
Unreviewed
CVE-2015-1555
was published
May 17, 2022
Windows Hyper-V in Windows 10 1607, 1703, and Windows Server 2016 allows a denial of service...
Moderate
Unreviewed
CVE-2017-8623
was published
May 17, 2022
A vulnerability in the Excel XLM macro parsing module in Clam AntiVirus (ClamAV) Software...
High
Unreviewed
CVE-2021-1252
was published
May 24, 2022
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General)....
Moderate
Unreviewed
CVE-2021-35594
was published
May 24, 2022
A vulnerability in the web-based management interface of Cisco Small Business RV110W, RV130,...
Critical
Unreviewed
CVE-2021-1459
was published
May 24, 2022
A vulnerability in the software-based SSL/TLS message handler of Cisco Firepower Threat Defense ...
High
Unreviewed
CVE-2021-1402
was published
May 24, 2022
Improper validation vulnerability in FeedsInfo prior to SMR Jun-2022 Release 1 allows attackers...
Critical
Unreviewed
CVE-2022-30711
was published
Jun 8, 2022
Improper validation vulnerability in LSOItemData prior to SMR Jun-2022 Release 1 allows attackers...
Critical
Unreviewed
CVE-2022-30713
was published
Jun 8, 2022
Improper validation vulnerability in RemoteViews prior to SMR Jun-2022 Release 1 allows attackers...
Critical
Unreviewed
CVE-2022-30710
was published
Jun 8, 2022
Improper input validation check logic vulnerability in SECRIL prior to SMR Jun-2022 Release 1...
Moderate
Unreviewed
CVE-2022-30709
was published
Jun 8, 2022
The web-based management interface on Cisco Small Business 220 devices with firmware before 1.0.1...
High
Unreviewed
CVE-2016-1472
was published
May 17, 2022
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code...
High
Unreviewed
CVE-2022-30232
was published
Jun 3, 2022
A vulnerability in Base Software for SoftControl allows an attacker to insert and run arbitrary...
Critical
Unreviewed
CVE-2020-24672
was published
May 24, 2022
Due to improper input sanitization, an authenticated user with certain specific privileges can...
High
Unreviewed
CVE-2021-38176
was published
May 24, 2022
A missing input validation in HDCP LDFW prior to SMR Nov-2021 Release 1 allows attackers to...
Moderate
Unreviewed
CVE-2021-25500
was published
May 24, 2022
A vulnerability in the web-based management interface of certain Cisco Small Business RV Series...
High
Unreviewed
CVE-2021-40120
was published
May 24, 2022
Unspecified vulnerability in sISAPILocation before 1.0.2.2 allows remote attackers to bypass...
Moderate
Unreviewed
CVE-2008-6298
was published
May 17, 2022
Insufficient input validation in PSP firmware for discrete TPM commands could allow a potential...
High
Unreviewed
CVE-2020-12946
was published
May 24, 2022
The Grapevine update process in Cisco Application Policy Infrastructure Controller Enterprise...
High
Unreviewed
CVE-2016-1365
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API