GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,986
Erlang
39
GitHub Actions
38
Go
2,626
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
954
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
463 advisories
Filter by severity
Python Facebook Thrift servers would not error upon receiving messages with containers of fields...
High
Unreviewed
CVE-2019-3558
was published
May 24, 2022
C++ Facebook Thrift servers (using cpp2) would not error upon receiving messages with containers...
High
Unreviewed
CVE-2019-3552
was published
May 24, 2022
Java Facebook Thrift servers would not error upon receiving messages with containers of fields of...
High
Unreviewed
CVE-2019-3559
was published
May 24, 2022
Fine Free file before 5.17 allows context-dependent attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2014-1943
was published
May 17, 2022
Bento4 v1.6.0.0 was discovered to contain a segmentation fault via the component /x86_64...
Moderate
Unreviewed
CVE-2022-29017
was published
May 17, 2022
A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services ...
Moderate
Unreviewed
CVE-2017-6628
was published
May 13, 2022
Improper Handling of Exceptional Conditions in Apache Tomcat
High
CVE-2017-5664
was published
for
org.apache.tomcat:tomcat
(Maven)
May 13, 2022
A vulnerability in the detection engine that handles Secure Sockets Layer (SSL) packets for Cisco...
Moderate
Unreviewed
CVE-2017-3887
was published
May 13, 2022
Huawei smart phones LYO-L21 with software LYO-L21C479B107, LYO-L21C479B107 have a privilege...
High
Unreviewed
CVE-2017-17172
was published
May 13, 2022
In Bitmap.ccp if Bitmap.nativeCreate fails an out of memory exception is not thrown leading to a...
High
Unreviewed
CVE-2017-13199
was published
May 13, 2022
The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel before 4.12...
High
Unreviewed
CVE-2017-11472
was published
May 13, 2022
A remote code execution vulnerability in the Android media framework (libstagefright). Product:...
High
Unreviewed
CVE-2017-0759
was published
May 13, 2022
A remote code execution vulnerability in the Android media framework (libstagefright). Product:...
High
Unreviewed
CVE-2017-0760
was published
May 13, 2022
A remote code execution vulnerability in the Android media framework (libhevc). Product: Android....
High
Unreviewed
CVE-2017-0762
was published
May 13, 2022
An elevation of privilege vulnerability in the Goodix touchscreen driver could enable a local...
High
Unreviewed
CVE-2017-0622
was published
May 13, 2022
Windows Hyper-V in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,...
High
Unreviewed
CVE-2017-0193
was published
May 13, 2022
A vulnerability in the ingress UDP packet processing functionality of Cisco Virtualized Packet...
High
Unreviewed
CVE-2017-6678
was published
May 13, 2022
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due...
High
Unreviewed
CVE-2017-7496
was published
May 13, 2022
A flaw was found in the Linux kernel before version 4.12 in the way the KVM module processed the...
High
Unreviewed
CVE-2017-7518
was published
May 13, 2022
Certain 802.11 network management messages have been determined to invoke wireless access point...
Moderate
Unreviewed
CVE-2017-9658
was published
May 13, 2022
Under specific 802.11 network conditions, a partial re-association of the Philips IntelliVue MX40...
Moderate
Unreviewed
CVE-2017-9657
was published
May 13, 2022
A vulnerability in the Secure Sockets Layer (SSL) Engine of Cisco Firepower System Software could...
Moderate
Unreviewed
CVE-2018-0272
was published
May 13, 2022
A vulnerability in the Session Initiation Protocol (SIP) call-handling functionality of Cisco IP...
High
Unreviewed
CVE-2018-0316
was published
May 13, 2022
A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in...
Critical
Unreviewed
CVE-2019-6256
was published
May 13, 2022
VeryNginx 0.3.3 allows remote attackers to bypass the Web Application Firewall feature because...
Critical
Unreviewed
CVE-2018-19991
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API