GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
Cross-site Scripting in Filter Stream Converter Application in XWiki Platform
High
CVE-2022-29258
was published
for
org.xwiki.platform:xwiki-platform-filter-ui
(Maven)
Jun 1, 2022
Cross-site Scripting in wiki manager join wiki page
High
CVE-2022-29252
was published
for
org.xwiki.platform:xwiki-platform-wiki-ui-mainwiki
(Maven)
May 25, 2022
Cross-site Scripting in the Flamingo theme manager
High
CVE-2022-29251
was published
for
org.xwiki.platform:xwiki-platform-flamingo-theme-ui
(Maven)
May 25, 2022
Improper Encoding or Escaping in Gallagher Command Centre Server allows a Command Centre Operator...
High
Unreviewed
CVE-2021-23205
was published
May 24, 2022
IBM Spectrum Scale 1.1.1.0 through 1.1.8.4 Transparent Cloud Tiering could allow a remote...
High
Unreviewed
CVE-2020-4850
was published
May 24, 2022
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to perform unauthorized...
High
Unreviewed
CVE-2021-20405
was published
May 24, 2022
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can...
High
Unreviewed
CVE-2020-35475
was published
May 24, 2022
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly...
High
Unreviewed
CVE-2020-24849
was published
May 24, 2022
A flaw was found in Ansible Collection community.crypto. openssl_privatekey_info exposes private...
High
Unreviewed
CVE-2020-25646
was published
May 24, 2022
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x...
High
Unreviewed
CVE-2020-26116
was published
May 24, 2022
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD)...
High
Unreviewed
CVE-2019-12675
was published
May 24, 2022
Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD)...
High
Unreviewed
CVE-2019-12674
was published
May 24, 2022
LibreOffice documents can contain macros. The execution of those macros is controlled by the...
High
Unreviewed
CVE-2019-9853
was published
May 24, 2022
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary...
High
Unreviewed
CVE-2018-16386
was published
May 24, 2022
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special...
High
Unreviewed
CVE-2016-3063
was published
May 17, 2022
Shell command injection in gitea
High
CVE-2022-30781
was published
for
code.gitea.io/gitea
(Go)
May 17, 2022
The csv_log_html function in library/edihistory/edih_csv_inc.php in OpenEMR 5.0.0 and prior...
High
Unreviewed
CVE-2017-12064
was published
May 13, 2022
contrib/completion/git-prompt.sh in Git before 1.9.3 does not sanitize branch names in the PS1...
High
Unreviewed
CVE-2014-9938
was published
May 13, 2022
A remote code execution vulnerability exists in Microsoft Dynamics 365 (on-premises) version 8...
High
Unreviewed
CVE-2018-8609
was published
May 13, 2022
Improper neutralization of escape vulnerability in Log Exporter in Synology DiskStation Manager ...
High
Unreviewed
CVE-2018-8920
was published
May 13, 2022
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended...
High
Unreviewed
CVE-2013-4547
was published
May 13, 2022
pkexec, when used with --user nonpriv, allows local users to escape to the parent session via a...
High
Unreviewed
CVE-2016-2568
was published
May 13, 2022
IBM Maximo Asset Management 7.6.1.1 and 7.6.1.2 is vulnerable to HTTP header injection, caused by...
High
Unreviewed
CVE-2021-29854
was published
May 4, 2022
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior...
High
Unreviewed
CVE-2022-0935
was published
Apr 8, 2022
An issue was discovered on DCN (Digital China Networks) S4600-10P-SI devices before R0241.0470....
High
Unreviewed
CVE-2021-42324
was published
Apr 6, 2022
ProTip!
Advisories are also available from the
GraphQL API