GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,211 advisories
Filter by severity
libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does...
Moderate
Unreviewed
CVE-2010-0420
was published
May 2, 2022
PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1...
Moderate
Unreviewed
CVE-2010-0394
was published
May 2, 2022
Multiple unrestricted file upload vulnerabilities in (1) register.php and (2) addvideo.php in...
Moderate
Unreviewed
CVE-2010-0366
was published
May 2, 2022
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote...
Moderate
Unreviewed
CVE-2010-0308
was published
May 2, 2022
The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.2 on Linux allows...
Moderate
Unreviewed
CVE-2010-0312
was published
May 2, 2022
mystring.c in hybserv in IRCD-Hybrid (aka Hybrid2 IRC Services) 1.9.2 through 1.9.4 allows remote...
Moderate
Unreviewed
CVE-2010-0303
was published
May 2, 2022
ejabberd_c2s.erl in ejabberd before 2.1.3 allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2010-0305
was published
May 2, 2022
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Vista Gold does...
Moderate
Unreviewed
CVE-2010-0235
was published
May 2, 2022
Unspecified vulnerability in registry-key validation in the kernel in Microsoft Windows 2000 SP4,...
Moderate
Unreviewed
CVE-2010-0238
was published
May 2, 2022
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and...
Moderate
Unreviewed
CVE-2010-0234
was published
May 2, 2022
The XMLDocument::load function in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2,...
Moderate
Unreviewed
CVE-2010-0182
was published
May 2, 2022
Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, executes a mail...
Moderate
Unreviewed
CVE-2010-0181
was published
May 2, 2022
WebKit in Apple Safari before 4.0.5 does not properly validate the cross-origin loading of...
Moderate
Unreviewed
CVE-2010-0051
was published
May 2, 2022
The Hyper-V server implementation in Microsoft Windows Server 2008 Gold, SP2, and R2 on the x64...
Moderate
Unreviewed
CVE-2010-0026
was published
May 2, 2022
The SMTP component in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, and Server...
Moderate
Unreviewed
CVE-2010-0024
was published
May 2, 2022
The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a...
Moderate
Unreviewed
CVE-2009-5136
was published
May 2, 2022
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read...
Moderate
Unreviewed
CVE-2009-5135
was published
May 2, 2022
Open redirect vulnerability in awredir.pl in AWStats before 6.95 allows remote attackers to...
Moderate
Unreviewed
CVE-2009-5020
was published
May 2, 2022
Deliantra Server before 2.82 allows remote authenticated users to cause a denial of service ...
Moderate
Unreviewed
CVE-2009-4847
was published
May 2, 2022
MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during...
Moderate
Unreviewed
CVE-2009-4833
was published
May 2, 2022
Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to...
Moderate
Unreviewed
CVE-2009-4788
was published
May 2, 2022
The PayPal Website Payments Standard functionality in the Ubercart module 5.x before 5.x-1.9 and...
Moderate
Unreviewed
CVE-2009-4771
was published
May 2, 2022
Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a...
Moderate
Unreviewed
CVE-2009-4658
was published
May 2, 2022
Yaws 1.85 writes data to a log file without sanitizing non-printable characters, which might...
Moderate
Unreviewed
CVE-2009-4495
was published
May 2, 2022
mini_httpd 1.19 writes data to a log file without sanitizing non-printable characters, which...
Moderate
Unreviewed
CVE-2009-4490
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API