GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
10,772 advisories
Filter by severity
lnsfw1.sys 6.0.2900.5512 in Look 'n' Stop Firewall 2.06p4 and 2.07 allows local users to cause a...
Low
Unreviewed
CVE-2011-0652
was published
May 17, 2022
Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local...
Moderate
Unreviewed
CVE-2011-0721
was published
May 17, 2022
xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute...
High
Unreviewed
CVE-2011-0465
was published
May 17, 2022
The tor_realloc function in Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha does not...
Moderate
Unreviewed
CVE-2011-0491
was published
May 17, 2022
WebKit, as used in Apple Safari before 5.0.4 and iOS before 4.3, does not properly handle...
Moderate
Unreviewed
CVE-2011-0163
was published
May 17, 2022
functions/page_header.php in SquirrelMail 1.4.21 and earlier does not prevent page rendering...
Moderate
Unreviewed
CVE-2010-4554
was published
May 17, 2022
MobileSafari in Apple iOS before 4.3 does not properly implement application launching through...
Moderate
Unreviewed
CVE-2011-0158
was published
May 17, 2022
The Relevant Content module 5.x before 5.x-1.4 and 6.x before 6.x-1.5 for Drupal does not...
Moderate
Unreviewed
CVE-2010-4775
was published
May 17, 2022
Cisco Adaptive Security Appliances (ASA) 5500 series devices with software before 8.2(3) do not...
High
Unreviewed
CVE-2010-4679
was published
May 17, 2022
Regular Expression Denial-of-Service in npm schema-inspector
High
CVE-2021-21267
was published
for
schema-inspector
(npm)
Mar 19, 2021
Path traversal in elFinder.NetCore
High
CVE-2021-23428
was published
for
elFinder.NetCore
(NuGet)
Sep 2, 2021
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a...
Moderate
Unreviewed
CVE-2021-4068
was published
Dec 24, 2021
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote...
Moderate
Unreviewed
CVE-2021-4059
was published
Dec 24, 2021
This issue was addressed with a new entitlement. This issue is fixed in macOS Monterey 12.3. An...
Moderate
Unreviewed
CVE-2022-22660
was published
Mar 19, 2022
A user interface issue was addressed. This issue is fixed in watchOS 8.5, Safari 15.4. Visiting a...
Moderate
Unreviewed
CVE-2022-22654
was published
Mar 19, 2022
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions...
Moderate
Unreviewed
CVE-2021-4219
was published
Mar 24, 2022
A logic issue was addressed with improved restrictions. This issue is fixed in iOS 15.4 and...
High
Unreviewed
CVE-2022-22653
was published
Mar 19, 2022
SolarWinds received a report of a vulnerability related to an input that was not sanitized in...
High
Unreviewed
CVE-2021-35254
was published
Mar 26, 2022
GE UR firmware versions prior to version 8.1x web server task does not properly handle receipt of...
Moderate
Unreviewed
CVE-2021-27420
was published
Mar 24, 2022
Improper Input Validation vulnerability in request line parsing of Apache Traffic Server allows...
High
Unreviewed
CVE-2021-44040
was published
Mar 24, 2022
The lack of validation of a key-value field in the Splunk-to-Splunk protocol results in a denial...
High
Unreviewed
CVE-2021-3422
was published
Mar 26, 2022
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote...
Critical
Unreviewed
CVE-2022-27228
was published
Mar 23, 2022
This vulnerability can be exploited by parsing maliciously crafted project files with Horner...
High
Unreviewed
CVE-2021-44462
was published
Mar 26, 2022
Unrestricted Upload of File with Dangerous Type in Gogs
High
CVE-2022-0415
was published
for
gogs.io/gogs
(Go)
Mar 28, 2022
Apple iOS before 4.2 does not properly validate signatures before displaying a configuration...
Moderate
Unreviewed
CVE-2010-3827
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API