GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,064 advisories
Filter by severity
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through...
Low
Unreviewed
CVE-2008-5161
was published
May 14, 2022
Microsoft Edge mishandles the Referer policy, which allows remote attackers to obtain sensitive...
Low
Unreviewed
CVE-2016-0125
was published
May 14, 2022
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,...
Low
Unreviewed
CVE-2016-0175
was published
May 14, 2022
The GDI component in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008...
Low
Unreviewed
CVE-2016-3251
was published
May 14, 2022
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows...
Low
Unreviewed
CVE-2016-3272
was published
May 14, 2022
Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows...
Low
Unreviewed
CVE-2016-3291
was published
May 14, 2022
Microsoft Internet Explorer 10 and 11 load different files for attempts to open a file:// URL...
Low
Unreviewed
CVE-2016-3321
was published
May 14, 2022
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to obtain sensitive...
Low
Unreviewed
CVE-2016-3325
was published
May 14, 2022
The Secure Kernel Mode feature in Microsoft Windows 10 Gold and 1511 allows local users to obtain...
Low
Unreviewed
CVE-2016-3344
was published
May 14, 2022
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to obtain...
Low
Unreviewed
CVE-2016-3351
was published
May 14, 2022
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to bypass the...
Low
Unreviewed
CVE-2016-7199
was published
May 14, 2022
Microsoft Edge allows remote attackers to access arbitrary "My Documents" files via a crafted web...
Low
Unreviewed
CVE-2016-7204
was published
May 14, 2022
Virtual Secure Mode in Microsoft Windows 10 allows local users to obtain sensitive information...
Low
Unreviewed
CVE-2016-7220
was published
May 14, 2022
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,...
Low
Unreviewed
CVE-2016-7214
was published
May 14, 2022
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote...
Low
Unreviewed
CVE-2016-7227
was published
May 14, 2022
An issue was discovered in Open-Xchange OX App Suite before 7.8.1-rev10. App Suite frontend...
Low
Unreviewed
CVE-2016-4027
was published
May 14, 2022
Exposure of Sensitive Information to an Unauthorized Actor in JBoss Fuse
Low
CVE-2014-0085
was published
for
org.jboss.fuse:jboss-fuse
(Maven)
May 14, 2022
The emulation routines for unspecified X86 devices in Xen 3.2.x through 4.5.x does not properly...
Low
Unreviewed
CVE-2015-2044
was published
May 14, 2022
The alloc_domain_struct function in arch/arm/domain.c in Xen 4.4.x, when running on an ARM...
Low
Unreviewed
CVE-2014-4022
was published
May 14, 2022
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data...
Low
Unreviewed
CVE-2015-2045
was published
May 14, 2022
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10...
Low
Unreviewed
CVE-2016-7714
was published
May 14, 2022
The download implementation in Google Chrome before 53.0.2785.89 on Windows and OS X and before...
Low
Unreviewed
CVE-2016-5166
was published
May 14, 2022
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other...
Low
Unreviewed
CVE-2013-4242
was published
May 14, 2022
libvirt before 1.2.12 allow remote authenticated users to obtain the VNC password by using the...
Low
Unreviewed
CVE-2015-0236
was published
May 14, 2022
Xen 4.2.x through 4.5.x does not initialize certain fields, which allows certain remote service...
Low
Unreviewed
CVE-2015-3340
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API