GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
281,010 advisories
Filter by severity
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3...
Moderate
Unreviewed
CVE-2010-1658
was published
May 17, 2022
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to elevate privileges due to the...
Moderate
Unreviewed
CVE-2017-8642
was published
May 17, 2022
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5...
High
Unreviewed
CVE-2014-8903
was published
May 17, 2022
Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools)...
Moderate
Unreviewed
CVE-2010-1547
was published
May 17, 2022
IBM AppScan Enterprise Edition 9.0 contains an unspecified vulnerability that could allow an...
High
Unreviewed
CVE-2016-9981
was published
May 17, 2022
Microsoft Edge in Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute...
High
Unreviewed
CVE-2017-8639
was published
May 17, 2022
Windows Hyper-V in Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold,...
High
Unreviewed
CVE-2017-8664
was published
May 17, 2022
A length validation (leading to out-of-bounds read and write) flaw was found in the way...
High
Unreviewed
CVE-2017-11670
was published
May 17, 2022
The Newsletter WordPress plugin before 7.4.5 does not sanitize and escape the $_SERVER[...
Moderate
Unreviewed
CVE-2022-1756
was published
Jun 14, 2022
The WP Statistics WordPress plugin before 13.2.2 does not sanitise the REQUEST_URI parameter...
Moderate
Unreviewed
CVE-2022-1005
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the...
Critical
Unreviewed
CVE-2022-30923
was published
Jun 9, 2022
The Discy WordPress theme before 5.2 lacks CSRF checks in some AJAX actions, allowing an attacker...
Moderate
Unreviewed
CVE-2022-1421
was published
Jun 9, 2022
The Discy WordPress theme before 5.2 does not check for CSRF tokens in the AJAX action...
Moderate
Unreviewed
CVE-2022-1422
was published
Jun 9, 2022
ToaruOS 1.99.2 is affected by incorrect access control via the kernel. Improper MMU management...
High
Unreviewed
CVE-2021-36710
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the...
Critical
Unreviewed
CVE-2022-30912
was published
Jun 9, 2022
Cross-site Scripting in RosarioSIS
Moderate
CVE-2022-1997
was published
for
francoisjacquet/rosariosis
(Composer)
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the CMD...
Critical
Unreviewed
CVE-2022-30909
was published
Jun 9, 2022
A vulnerability, which was classified as critical, has been found in The Next Generation of...
High
Unreviewed
CVE-2017-20017
was published
Jun 9, 2022
There is a SQL Injection vulnerability in ChurchCRM 4.4.5 via the 'PersonID' field in /churchcrm...
High
Unreviewed
CVE-2022-31325
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the GO...
Critical
Unreviewed
CVE-2022-30910
was published
Jun 9, 2022
H3C Magic R100 R100V100R005 was discovered to contain a stack overflow vulnerability via the...
Critical
Unreviewed
CVE-2022-30925
was published
Jun 9, 2022
The WP Born Babies WordPress plugin through 1.0 does not sanitise and escape some of its fields,...
Moderate
Unreviewed
CVE-2022-1506
was published
Jun 9, 2022
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise...
High
Unreviewed
CVE-2022-43522
was published
Jan 5, 2023
In Garmin Connect 4.61, terminating a LiveTrack session wouldn't prevent the LiveTrack API from...
High
Unreviewed
CVE-2022-46081
was published
Jan 4, 2023
Multiple vulnerabilities in the web-based management interface of Aruba EdgeConnect Enterprise...
High
Unreviewed
CVE-2022-43520
was published
Jan 5, 2023
ProTip!
Advisories are also available from the
GraphQL API