GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
838 advisories
Filter by severity
A vulnerability in the Snort detection engine integration for Cisco Firepower Threat Defense (FTD...
High
Unreviewed
CVE-2022-20751
was published
May 4, 2022
Tenda AC15 US_AC15V1.0BR_V15.03.05.20_multi_TDE01.bin is vulnerable to Buffer Overflow. The stack...
High
Unreviewed
CVE-2022-28556
was published
May 5, 2022
An issue has been discovered in GitLab affecting all versions before 14.8.6, all versions...
Moderate
Unreviewed
CVE-2022-1428
was published
May 12, 2022
An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6,...
High
Unreviewed
CVE-2022-1510
was published
May 12, 2022
Denial of service in Spring Framework
High
CVE-2022-22970
was published
for
org.springframework:spring-beans
(Maven)
May 13, 2022
Allocation of Resources Without Limits or Throttling in Spring Framework
Moderate
CVE-2022-22971
was published
for
org.springframework:spring-messaging
(Maven)
May 13, 2022
It was found in Ceph versions before 13.2.4 that authenticated ceph RGW users can cause a denial...
Moderate
Unreviewed
CVE-2018-16846
was published
May 13, 2022
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher...
Critical
Unreviewed
CVE-2018-20033
was published
May 13, 2022
The _zip_read_eocd64 function in zip_open.c in libzip before 1.3.0 mishandles EOCD records, which...
Moderate
Unreviewed
CVE-2017-14107
was published
May 13, 2022
A vulnerability in the processing of IP Service Level Agreement (SLA) packets by Cisco IOS...
High
Unreviewed
CVE-2019-1737
was published
May 13, 2022
The jv_dump_term function in jq 1.5 allows remote attackers to cause a denial of service (stack...
High
Unreviewed
CVE-2016-4074
was published
May 13, 2022
ABB, Phoenix Contact, Schneider Electric, Siemens, WAGO - Programmable Logic Controllers,...
High
Unreviewed
CVE-2019-10953
was published
May 13, 2022
An allocation of memory without limits, that could result in the stack clashing with another...
High
Unreviewed
CVE-2018-16864
was published
May 13, 2022
An allocation of memory without limits, that could result in the stack clashing with another...
High
Unreviewed
CVE-2018-16865
was published
May 13, 2022
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed...
Moderate
Unreviewed
CVE-2019-9073
was published
May 13, 2022
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed...
Moderate
Unreviewed
CVE-2019-9076
was published
May 13, 2022
An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed...
Moderate
Unreviewed
CVE-2019-9072
was published
May 13, 2022
A flaw was found in glusterfs server through versions 4.1.4 and 3.1.2 which allowed repeated...
Moderate
Unreviewed
CVE-2018-14660
was published
May 13, 2022
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service ...
Moderate
Unreviewed
CVE-2019-9705
was published
May 13, 2022
On EX2300, EX3400, EX4600, QFX3K and QFX5K series, firewall filter configuration cannot perform...
Moderate
Unreviewed
CVE-2019-0005
was published
May 13, 2022
Crafted packets destined to the management interface (fxp0) of an SRX340 or SRX345 services...
Moderate
Unreviewed
CVE-2019-0038
was published
May 13, 2022
The xhci_ring_fetch function in hw/usb/hcd-xhci.c in QEMU (aka Quick Emulator) allows local guest...
Moderate
Unreviewed
CVE-2016-8576
was published
May 13, 2022
Stack consumption vulnerability in the fnmatch implementation in apr_fnmatch.c in the Apache...
Moderate
Unreviewed
CVE-2011-0419
was published
May 13, 2022
Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js...
High
Unreviewed
CVE-2019-5739
was published
May 13, 2022
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before...
High
Unreviewed
CVE-2019-5737
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API