GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,210 advisories
Filter by severity
Joomla! 1.5 before RC2 (aka Endeleo) allows remote attackers to obtain sensitive information (the...
Moderate
Unreviewed
CVE-2007-4780
was published
May 1, 2022
Alien Arena 2007 6.10 and earlier allows remote attackers to cause a denial of service (client...
Moderate
Unreviewed
CVE-2007-4755
was published
May 1, 2022
Claroline before 1.8.6 allows remote authenticated administrators to obtain sensitive information...
Moderate
Unreviewed
CVE-2007-4742
was published
May 1, 2022
PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when...
Moderate
Unreviewed
CVE-2007-4744
was published
May 1, 2022
Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun...
Moderate
Unreviewed
CVE-2007-4732
was published
May 1, 2022
Unspecified "input validation" vulnerability in WebCore in Apple Mac OS X 10.4 through 10.4.10...
Moderate
Unreviewed
CVE-2007-4695
was published
May 1, 2022
Unspecified vulnerability in Safari in Apple iPhone 1.1.1, and Safari 3 before Beta Update 3.0.4...
Moderate
Unreviewed
CVE-2007-4671
was published
May 1, 2022
Yahoo! Messenger 8.1.0.209 and 8.1.0.402 allows remote attackers to cause a denial of service ...
Moderate
Unreviewed
CVE-2007-4635
was published
May 1, 2022
CRLF injection vulnerability in contact.php in Moonware (aka Dale Mooney Gallery) allows remote...
Moderate
Unreviewed
CVE-2007-4612
was published
May 1, 2022
OpenSymphony XWork vulnerable to improper input validation
Moderate
CVE-2007-4556
was published
for
opensymphony:xwork
(Maven)
May 1, 2022
The Volume Manager Scheduler Service (aka VxSchedService.exe) in Symantec Veritas Storage...
Moderate
Unreviewed
CVE-2007-4516
was published
May 1, 2022
The server in Toribash 2.71 and earlier does not properly handle long commands, which allows...
Moderate
Unreviewed
CVE-2007-4450
was published
May 1, 2022
Unspecified vulnerability in Cisco IOS 12.0 through 12.4 allows context-dependent attackers to...
Moderate
Unreviewed
CVE-2007-4430
was published
May 1, 2022
The wordwrap function in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, does not properly use the...
Moderate
Unreviewed
CVE-2007-3998
was published
May 1, 2022
The glob function in PHP 5.2.3 allows context-dependent attackers to cause a denial of service...
Moderate
Unreviewed
CVE-2007-3806
was published
May 1, 2022
The session_start function in ext/session in PHP 4.x up to 4.4.7 and 5.x up to 5.2.3 allows...
Moderate
Unreviewed
CVE-2007-3799
was published
May 1, 2022
MySQL Community Server before 5.0.45 allows remote attackers to cause a denial of service (daemon...
Moderate
Unreviewed
CVE-2007-3780
was published
May 1, 2022
Mail in Apple iPhone 1.1.1 allows remote user-assisted attackers to force the iPhone user to make...
Moderate
Unreviewed
CVE-2007-3755
was published
May 1, 2022
Safari in Apple iPhone 1.1.1 allows remote user-assisted attackers to trick the iPhone user into...
Moderate
Unreviewed
CVE-2007-3757
was published
May 1, 2022
The Linux kernel 2.6.20 and 2.6.21 does not properly handle an invalid LDT segment selector in ...
Moderate
Unreviewed
CVE-2007-3731
was published
May 1, 2022
Wireshark before 0.99.6 allows remote attackers to cause a denial of service (crash) via a...
Moderate
Unreviewed
CVE-2007-3389
was published
May 1, 2022
WebKit in Apple Safari 3 Beta before Update 3.0.3 does not properly recognize an unchecked ...
Moderate
Unreviewed
CVE-2007-2408
was published
May 1, 2022
CRLF injection vulnerability in the Digest Authentication support for Mozilla Firefox before 2.0...
Moderate
Unreviewed
CVE-2007-2292
was published
May 1, 2022
A typo in Linux kernel 2.6 before 2.6.21-rc6 and 2.4 before 2.4.35 causes RTA_MAX to be used as...
Moderate
Unreviewed
CVE-2007-2172
was published
May 1, 2022
bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not...
Moderate
Unreviewed
CVE-2007-1995
was published
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API