GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,233
Erlang
31
GitHub Actions
20
Go
1,992
Maven
5,000+
npm
3,709
NuGet
661
pip
3,346
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
157 advisories
Filter by severity
Composer allows cache poisoning from other projects built on the same host
High
CVE-2015-8371
was published
for
composer/composer
(Composer)
Sep 21, 2023
hammer_cli_foreman Improper Certificate Validation vulnerability
High
CVE-2017-2667
was published
for
hammer_cli_foreman
(RubyGems)
May 13, 2022
Vulnerability of trust relationships being inaccurate in distributed scenarios. Successful...
High
Unreviewed
CVE-2023-52109
was published
Jan 16, 2024
Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote...
High
Unreviewed
CVE-2023-5482
was published
Nov 1, 2023
Magento 2 Community Edition Security Bypass
High
CVE-2019-8112
was published
for
magento/community-edition
(Composer)
May 24, 2022
A vulnerability in the iPXE boot function of Cisco IOS XR software could allow an authenticated,...
High
Unreviewed
CVE-2023-20236
was published
Sep 13, 2023
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the...
High
Unreviewed
CVE-2022-30272
was published
Jul 27, 2022
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware...
High
Unreviewed
CVE-2022-30260
was published
Dec 26, 2022
When the Node.js policy feature checks the integrity of a resource against a trusted manifest,...
High
Unreviewed
CVE-2023-38552
was published
Oct 18, 2023
Spring Security vulnerable to Authorization Bypass
High
CVE-2018-15801
was published
for
org.springframework.security:spring-security-core
(Maven)
Dec 20, 2018
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the...
High
Unreviewed
CVE-2019-3786
was published
May 24, 2022
A vulnerability in Cisco Advanced Malware Protection (AMP) for Endpoints for Windows could allow...
High
Unreviewed
CVE-2019-1932
was published
May 24, 2022
Mirror zones are a BIND feature allowing recursive servers to pre-cache zone data provided by...
High
Unreviewed
CVE-2019-6475
was published
May 24, 2022
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated...
High
Unreviewed
CVE-2019-3979
was published
May 24, 2022
A vulnerability in the hardware crypto driver of Cisco IOS XE Software for Cisco 4300 Series...
High
Unreviewed
CVE-2020-3220
was published
May 24, 2022
Altenergy Power Control Software C1.2.5 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2023-31502
was published
May 12, 2023
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto...
High
Unreviewed
CVE-2023-2866
was published
Jun 7, 2023
Insufficient verification of data authenticity in Zoom for Windows clients before 5.14.0 may...
High
Unreviewed
CVE-2023-34113
was published
Jun 13, 2023
The driver installation package created by Printer Driver Packager NX v1.0.02 to v1.1.25 fails to...
High
Unreviewed
CVE-2023-30759
was published
Jun 19, 2023
Rumpus - FTP server version 9.0.7.1 Improper Token Verification– vulnerability may allow...
High
Unreviewed
CVE-2022-46370
was published
Jul 6, 2023
In JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be...
High
Unreviewed
CVE-2022-48431
was published
Jul 6, 2023
Insufficient verification of data authenticity in Zoom Desktop Client for Windows before 5.14.5...
High
Unreviewed
CVE-2023-36541
was published
Aug 8, 2023
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of...
High
Unreviewed
CVE-2023-22955
was published
Aug 11, 2023
Insufficient verification of data authenticity vulnerability in Delinea Secret Server, in its v10...
High
Unreviewed
CVE-2023-4589
was published
Sep 6, 2023
ProTip!
Advisories are also available from the
GraphQL API