GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,150
Maven
5,000+
npm
3,815
NuGet
690
pip
3,490
Pub
12
RubyGems
902
Rust
900
Swift
38
Unreviewed advisories
All unreviewed
5,000+
67 advisories
Filter by severity
An exploitable firmware modification vulnerability was discovered in WNR612v2 Wireless Routers...
High
Unreviewed
CVE-2023-23110
was published
Feb 2, 2023
Sinatra vulnerable to Reflected File Download attack
High
CVE-2022-45442
was published
for
sinatra
(RubyGems)
Nov 30, 2022
Data Integrity Failure in 'Backup Config' in D-Link DNR-322L <= 2.60B15 allows an authenticated...
High
Unreviewed
CVE-2022-40799
was published
Nov 29, 2022
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the...
High
Unreviewed
CVE-2022-36671
was published
Sep 2, 2022
An arbitrary file download vulnerability in Oliver v5 Library Server Versions < 5.00.008.053 via...
High
Unreviewed
CVE-2021-45027
was published
Sep 2, 2022
Django vulnerable to Reflected File Download attack
High
CVE-2022-36359
was published
for
Django
(pip)
Aug 11, 2022
A vulnerability exists in the file upload validation part of Hitachi Energy TXpert Hub CoreTec 4...
High
Unreviewed
CVE-2021-35532
was published
Jun 8, 2022
Caphyon Ltd Advanced Installer 19.2 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2022-27438
was published
Jun 7, 2022
A CWE-494: Download of Code Without Integrity Check vulnerability exists in PLC Simulator on...
High
Unreviewed
CVE-2020-28213
was published
May 24, 2022
DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote...
High
Unreviewed
CVE-2020-7875
was published
May 24, 2022
Download of code without integrity check vulnerability in NEXACRO14 Runtime ActiveX control of...
High
Unreviewed
CVE-2020-7874
was published
May 24, 2022
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC...
High
Unreviewed
CVE-2021-38588
was published
May 24, 2022
Tencent GameLoop before 4.1.21.90 downloaded updates over an insecure HTTP connection. A...
High
Unreviewed
CVE-2021-33879
was published
May 24, 2022
An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check,...
High
Unreviewed
CVE-2021-27574
was published
May 24, 2022
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...
High
Unreviewed
CVE-2020-1452
was published
May 24, 2022
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...
High
Unreviewed
CVE-2020-1453
was published
May 24, 2022
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...
High
Unreviewed
CVE-2020-1200
was published
May 24, 2022
An issue was discovered in WeeChat before 2.7.1 (0.4.0 to 2.7 are affected). A malformed message...
High
Unreviewed
CVE-2020-9759
was published
May 24, 2022
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where...
High
Unreviewed
CVE-2019-3977
was published
May 24, 2022
The Cobham EXPLORER 710, firmware version 1.07, does not validate its firmware image. Development...
High
Unreviewed
CVE-2019-9534
was published
May 24, 2022
Cargo prior to Rust 1.26.0 may download the wrong dependency
High
CVE-2019-16760
was published
for
cargo
(Rust)
May 24, 2022
Philips IntelliVue WLAN, portable patient monitors, WLAN Version A, Firmware A.03.09, WLAN...
High
Unreviewed
CVE-2019-13534
was published
May 24, 2022
Yes24ViewerX ActiveX Control 1.0.327.50126 and earlier versions contains a vulnerability that...
High
Unreviewed
CVE-2019-12809
was published
May 24, 2022
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its...
High
Unreviewed
CVE-2019-7229
was published
May 24, 2022
Incorrect Resource Transfer Between Spheres in Grails
High
CVE-2019-12728
was published
for
org.grails:grails-core
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API