GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
66 advisories
Filter by severity
In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3,...
High
Unreviewed
CVE-2018-6560
was published
May 13, 2022
An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of...
High
Unreviewed
CVE-2018-19966
was published
May 13, 2022
bgpd in FRRouting FRR (aka Free Range Routing) 2.x and 3.x before 3.0.4, 4.x before 4.0.1, 5.x...
Moderate
Unreviewed
CVE-2019-5892
was published
May 13, 2022
Broken Authorization in ZITADEL Actions
High
CVE-2022-36051
was published
for
github.com/zitadel/zitadel
(Go)
Aug 30, 2022
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) feature of Cisco NX...
High
Unreviewed
CVE-2021-1587
was published
May 24, 2022
Firefox incorrectly treated an inline list-item element as a block element, resulting in an out...
High
Unreviewed
CVE-2021-29988
was published
May 24, 2022
An improper interpretation conflict of certain data between certain software components within...
High
Unreviewed
CVE-2021-0207
was published
May 24, 2022
Netty vulnerable to HTTP Response splitting from assigning header value iterator
Moderate
CVE-2022-41915
was published
for
io.netty:netty-codec-http
(Maven)
Dec 12, 2022
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP...
Moderate
Unreviewed
CVE-2020-9363
was published
May 24, 2022
The Quick Heal AV parsing engine (November 2019) allows virus-detection bypass via a crafted...
Moderate
Unreviewed
CVE-2020-9362
was published
May 24, 2022
Go before 1.12.11 and 1.3.x before 1.13.2 can panic upon an attempt to process network traffic...
Moderate
Unreviewed
CVE-2019-17596
was published
May 24, 2022
A vulnerability in the implementation of IPv6 VPN over MPLS (6VPE) with Zone-Based Firewall (ZBFW...
High
Unreviewed
CVE-2022-20915
was published
Oct 11, 2022
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558...
Moderate
Unreviewed
CVE-2021-41437
was published
Sep 27, 2022
Fossil 2.18 on Windows allows attackers to cause a denial of service (daemon crash) via an XSS...
Moderate
Unreviewed
CVE-2022-34009
was published
Jul 29, 2022
Failed payment recorded has completed in Silverstripe Omnipay
Low
CVE-2022-29254
was published
for
silverstripe/silverstripe-omnipay
(Composer)
Jun 6, 2022
A null byte interaction error has been discovered in the code that the telnetd_startup daemon...
High
Unreviewed
CVE-2022-25219
was published
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API