GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,969
Erlang
39
GitHub Actions
38
Go
2,620
Maven
5,000+
npm
4,255
NuGet
760
pip
4,043
Pub
12
RubyGems
953
Rust
1,050
Swift
45
Unreviewed advisories
All unreviewed
5,000+
63 advisories
Filter by severity
toui allows user-specific variables to be shared between users
Critical
CVE-2023-33175
was published
for
toui
(pip)
May 24, 2023
sqlite vulnerable to code execution due to Object coercion
High
CVE-2022-43441
was published
for
sqlite3
(npm)
Mar 13, 2023
CRI-O vulnerable to /etc/passwd tampering resulting in Privilege Escalation
Moderate
CVE-2022-4318
was published
for
github.com/cri-o/cri-o
(Go)
Dec 29, 2022
vm2 vulnerable to Sandbox Escape resulting in Remote Code Execution on host
Critical
CVE-2022-36067
was published
for
vm2
(npm)
Sep 28, 2022
Budibase Improper Access Control vulnerability
Moderate
CVE-2022-3225
was published
for
@budibase/bbui
(npm)
Sep 17, 2022
CrafterCMS OS Command Injection vulnerability
High
CVE-2022-40635
was published
for
org.craftercms:craftercms
(Maven)
Sep 14, 2022
CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources
High
CVE-2022-40634
was published
for
org.craftercms:crafter-studio
(Maven)
Sep 14, 2022
Attacker might be able to execute malicious Perl code in the Template toolkit, by having the...
High
Unreviewed
CVE-2022-39051
was published
Sep 6, 2022
A vulnerability found in postgresql. On this security issue an attack requires permission to...
High
Unreviewed
CVE-2022-2625
was published
Aug 19, 2022
The Multipass service was found to have code paths that could be abused to cause a denial of...
Critical
Unreviewed
CVE-2022-27889
was published
Jun 15, 2022
There is an Improper Control of Dynamically Managing Code Resources Vulnerability in Huawei...
Critical
Unreviewed
CVE-2021-22387
was published
May 24, 2022
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a...
Critical
Unreviewed
CVE-2021-32563
was published
May 24, 2022
A vulnerability in Cisco Webex Meetings and Cisco Webex Meetings Server could allow an...
Critical
Unreviewed
CVE-2020-3419
was published
May 24, 2022
A vulnerability in the command-line interface in Brocade Fabric OS before Brocade Fabric OS v8.2...
Moderate
Unreviewed
CVE-2020-15372
was published
May 24, 2022
An information disclosure vulnerability exists when the Windows GDI component improperly...
Moderate
Unreviewed
CVE-2020-1097
was published
May 24, 2022
An information disclosure vulnerability exists when the Windows GDI component improperly...
Moderate
Unreviewed
CVE-2020-1091
was published
May 24, 2022
There was a man-in-the-middle (MITM) vulnerability present in the Confluence Previews plugin in...
Moderate
Unreviewed
CVE-2019-15006
was published
May 24, 2022
GitHub Enterprise before 20120304 does not properly restrict the use of a hash to provide values...
Moderate
Unreviewed
CVE-2012-2055
was published
May 17, 2022
Crafter CMS Crafter Studio vulnerable to Improper Control of Dynamically-Managed Code Resources
High
CVE-2021-23267
was published
for
org.craftercms:crafter-studio
(Maven)
May 17, 2022
distribute-cache.c in ImageMagick re-uses objects after they have been destroyed, which allows...
Critical
Unreviewed
CVE-2014-9852
was published
May 14, 2022
A vulnerability in the Fibre Channel over Ethernet (FCoE) protocol implementation in Cisco NX-OS...
Moderate
Unreviewed
CVE-2019-1595
was published
May 13, 2022
A vulnerability in the Fibre Channel over Ethernet (FCoE) N-port Virtualization (NPV) protocol...
High
Unreviewed
CVE-2019-1617
was published
May 13, 2022
In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they...
High
Unreviewed
CVE-2022-25265
was published
Feb 17, 2022
ProTip!
Advisories are also available from the
GraphQL API