GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
305,525 advisories
Filter by severity
Potrace 1.14 has a heap-based buffer over-read in the interpolate_cubic function in mkbitmap.c.
High
Unreviewed
CVE-2017-12067
was published
May 17, 2022
A vulnerability in the web interface of the Cisco Web Security Appliance (WSA) could allow an...
High
Unreviewed
CVE-2017-6746
was published
May 17, 2022
Buffer overflow in drivers/soc/qcom/subsystem_restart.c in the Qualcomm subsystem driver in...
High
Unreviewed
CVE-2016-3858
was published
May 17, 2022
Vulnerability in the Oracle Agile PLM component of Oracle Supply Chain Products Suite ...
Moderate
Unreviewed
CVE-2017-10093
was published
May 17, 2022
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a...
High
Unreviewed
CVE-2015-6585
was published
May 17, 2022
EMC Isilon OneFS 7.1.x and 7.2.x before 7.2.1.3 and 8.0.x before 8.0.0.1, and IsilonSD Edge OneFS...
Moderate
Unreviewed
CVE-2016-0907
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in login.php in EsPartenaires 1.0 allows remote...
Moderate
Unreviewed
CVE-2008-6876
was published
May 17, 2022
Multiple PHP remote file inclusion vulnerabilities in V-webmail 1.6.4 allow remote attackers to...
Moderate
Unreviewed
CVE-2008-6840
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in search.php in Zoph 0.7.2.1 allows remote attackers to...
Moderate
Unreviewed
CVE-2008-6838
was published
May 17, 2022
Avira AntiVir Premium, Premium Security Suite, AntiVir Professional, and AntiVir Personal - FREE...
High
Unreviewed
CVE-2008-6962
was published
May 17, 2022
login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote...
Moderate
Unreviewed
CVE-2008-6896
was published
May 17, 2022
Multiple unspecified vulnerabilities in Sophos SAVScan 4.33.0 for Linux, and possibly other...
High
Unreviewed
CVE-2008-6904
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in login.php in 3CX Phone System Free Edition...
Moderate
Unreviewed
CVE-2008-6894
was published
May 17, 2022
The writeRandomBytes_RtlGenRandom function in xmlparse.c in libexpat in Expat 2.2.1 and 2.2.2 on...
High
Unreviewed
CVE-2017-11742
was published
May 17, 2022
Reporter.exe in Acunetix 8 allows remote attackers to execute arbitrary code or cause a denial of...
Critical
Unreviewed
CVE-2017-11673
was published
May 17, 2022
NVIDIA GPU Display Driver contains a vulnerability in the kernel mode layer handler where an...
High
Unreviewed
CVE-2017-6259
was published
May 17, 2022
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer helper...
Moderate
Unreviewed
CVE-2017-6260
was published
May 17, 2022
Emlog Pro v 1.0.4 cross-site scripting (XSS) in Emlog Pro background management.
Moderate
Unreviewed
CVE-2021-40610
was published
Jun 10, 2022
Server-Side Request Forgery in kityminder
Critical
CVE-2022-31830
was published
for
kityminder
(npm)
Jun 10, 2022
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. The transmission...
Moderate
Unreviewed
CVE-2022-25805
was published
Jun 10, 2022
Due to an insecure design, the Lepin EP-KP001 flash drive through KP001_V19 is vulnerable to an...
Moderate
Unreviewed
CVE-2022-29948
was published
Jun 11, 2022
In EMC RSA Authentication Manager 8.2 SP1 and earlier, a malicious RSA Security Console...
Moderate
Unreviewed
CVE-2017-8000
was published
May 17, 2022
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist...
High
Unreviewed
CVE-2022-29094
was published
Jun 11, 2022
dynamicMarkt <= 3.10 is affected by SQL injection in the kat parameter of index.php.
Critical
Unreviewed
CVE-2021-41756
was published
Jun 11, 2022
Directory traversal in convert-svg-core
High
CVE-2022-24278
was published
for
convert-svg-core
(npm)
Jun 11, 2022
ProTip!
Advisories are also available from the
GraphQL API