GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
41 advisories
Filter by severity
libcurl wrongly allows cookies to be set for Top Level Domains (TLDs) if thehost name is provided...
Moderate
Unreviewed
CVE-2022-27779
was published
Jun 3, 2022
A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling...
Moderate
Unreviewed
CVE-2020-27748
was published
May 24, 2022
A vulnerability in the CLI parser of Cisco IOS XR Software could allow an authenticated, local...
Moderate
Unreviewed
CVE-2021-1128
was published
May 24, 2022
A vulnerability in the authentication for the general purpose APIs implementation of Cisco...
Moderate
Unreviewed
CVE-2021-1129
was published
May 24, 2022
When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and...
Moderate
Unreviewed
CVE-2020-1774
was published
May 24, 2022
Support bundle generated files could contain sensitive information that might be unwanted to be...
Moderate
Unreviewed
CVE-2020-1770
was published
May 24, 2022
An information exposure vulnerability exists in gitlab.com <v12.3.2, <v12.2.6, and <v12.1.10 when...
Moderate
Unreviewed
CVE-2019-15580
was published
May 24, 2022
A vulnerability was found in 3scale before version 2.6, did not set the HTTPOnly attribute on the...
Moderate
Unreviewed
CVE-2019-14849
was published
May 24, 2022
A CSRF token visible in the URL may possibly lead to information disclosure vulnerability.
Moderate
Unreviewed
CVE-2022-27671
was published
Apr 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor and Insertion of Sensitive Information Into Sent Data in Calico
Moderate
CVE-2020-13597
was published
for
github.com/projectcalico/calico
(Go)
Feb 15, 2022
Remote Memory Exposure in mongoose
Moderate
GHSA-r5xw-q988-826m
was published
for
mongoose
(npm)
Sep 1, 2020
Remote Memory Disclosure in bittorrent-dht
Moderate
CVE-2016-10519
was published
for
bittorrent-dht
(npm)
Sep 1, 2020
Remote Memory Exposure in floody
Moderate
GHSA-3p92-886g-qxpq
was published
for
floody
(npm)
Jun 4, 2019
mysql Node.JS Module Vulnerable to Remote Memory Exposure
Moderate
GHSA-5f7m-mmpc-qhh4
was published
for
mysql
(npm)
May 23, 2019
Remote Memory Exposure in request
Moderate
CVE-2017-16026
was published
for
request
(npm)
Nov 9, 2018
keycloak-core discloses system properties
Moderate
CVE-2017-2582
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 18, 2018
ProTip!
Advisories are also available from the
GraphQL API