GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
9,966 advisories
Filter by severity
The Servlet Engine/Web Container and JSP components in IBM WebSphere Application Server (WAS) 5.1...
High
Unreviewed
CVE-2009-0508
was published
May 2, 2022
VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and...
Low
Unreviewed
CVE-2009-0518
was published
May 2, 2022
WSPolicy in the Web Services component in IBM WebSphere Application Server (WAS) 7.0.x before 7.0...
Low
Unreviewed
CVE-2009-0504
was published
May 2, 2022
The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module...
Moderate
Unreviewed
CVE-2009-0474
was published
May 2, 2022
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct...
Moderate
Unreviewed
CVE-2009-0453
was published
May 2, 2022
PerfServlet in the PMI/Performance Tools component in IBM WebSphere Application Server (WAS) 6.0...
Low
Unreviewed
CVE-2009-0434
was published
May 2, 2022
The Installation Factory installation process for IBM WebSphere Application Server (WAS) 6.0.2 on...
Low
Unreviewed
CVE-2009-0437
was published
May 2, 2022
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.0.1 on z/OS allows...
High
Unreviewed
CVE-2009-0391
was published
May 2, 2022
Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache...
Low
Unreviewed
CVE-2009-0358
was published
May 2, 2022
The login module in Sun Java System Access Manager 6 2005Q1 (aka 6.3), 7 2005Q4 (aka 7.0), and 7...
Moderate
Unreviewed
CVE-2009-0348
was published
May 2, 2022
Microsoft Windows XP, Server 2003 and 2008, and Vista exposes I/O activity measurements of all...
Moderate
Unreviewed
CVE-2009-0320
was published
May 2, 2022
Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web...
Moderate
Unreviewed
CVE-2009-0278
was published
May 2, 2022
Unspecified vulnerability in WebAccess in Novell GroupWise 6.5, 7.0, 7.01, 7.02x, 7.03, 7.03HP1a,...
Moderate
Unreviewed
CVE-2009-0274
was published
May 2, 2022
The Windows Printing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2,...
Moderate
Unreviewed
CVE-2009-0229
was published
May 2, 2022
Apple iTunes before 8.1 does not properly inform the user about the origin of an authentication...
Moderate
Unreviewed
CVE-2009-0143
was published
May 2, 2022
Unspecified vulnerability in Apple Safari on Mac OS X 10.5 and Windows allows remote attackers to...
High
Unreviewed
CVE-2009-0123
was published
May 2, 2022
IAX2 in Asterisk Open Source 1.2.x before 1.2.31, 1.4.x before 1.4.23-rc4, and 1.6.x before 1.6.0...
Moderate
Unreviewed
CVE-2009-0041
was published
May 2, 2022
Apple iPhone 2.1 with firmware 5F136, when Require Passcode is enabled and Show SMS Preview is...
Low
Unreviewed
CVE-2008-4593
was published
May 2, 2022
HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to obtain...
High
Unreviewed
CVE-2008-4560
was published
May 2, 2022
Apple Mail.app 3.5 on Mac OS X, when "Store draft messages on the server" is enabled, stores...
Moderate
Unreviewed
CVE-2008-4491
was published
May 2, 2022
The sctp_auth_ep_set_hmacs function in net/sctp/auth.c in the Stream Control Transmission...
Moderate
Unreviewed
CVE-2008-4445
was published
May 2, 2022
Unspecified vulnerability in HP Systems Insight Manager (SIM) before 5.2 Update 2 (C.05.02.02.00)...
Moderate
Unreviewed
CVE-2008-4412
was published
May 2, 2022
The Cisco Linksys WVC54GC wireless video camera before firmware 1.25 sends cleartext...
High
Unreviewed
CVE-2008-4390
was published
May 2, 2022
mod_userdir in lighttpd before 1.4.20, when a case-insensitive operating system or filesystem is...
High
Unreviewed
CVE-2008-4360
was published
May 2, 2022
lighttpd before 1.4.20 compares URIs to patterns in the (1) url.redirect and (2) url.rewrite...
High
Unreviewed
CVE-2008-4359
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API