GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,248
Erlang
31
GitHub Actions
21
Go
2,014
Maven
5,000+
npm
3,721
NuGet
662
pip
3,393
Pub
11
RubyGems
890
Rust
852
Swift
36
Unreviewed advisories
All unreviewed
5,000+
4,850 advisories
Filter by severity
Username spoofing in OnionShare
Moderate
CVE-2022-21696
was published
for
onionshare-cli
(pip)
Jan 21, 2022
OAuthLib vulnerable to DoS when attacker provides malicious IPV6 URI
Moderate
CVE-2022-36087
was published
for
oauthlib
(pip)
Sep 16, 2022
Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of...
Moderate
Unreviewed
CVE-2024-45871
was published
Oct 3, 2024
Apache Ambari: Various Cross site scripting problems
Moderate
CVE-2023-50378
was published
for
org.apache.ambari:ambari
(Maven)
Mar 1, 2024
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high...
Moderate
Unreviewed
CVE-2023-1620
was published
Jun 26, 2023
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple...
Moderate
Unreviewed
CVE-2023-2673
was published
Jun 13, 2023
Multiple WAGO devices in multiple versions may allow an authenticated remote attacker with high...
Moderate
Unreviewed
CVE-2023-1619
was published
Jun 26, 2023
In connectivity system driver, there is a possible out of bounds write due to improper input...
Moderate
Unreviewed
CVE-2023-32811
was published
Sep 4, 2023
The fix for CVE-2024-2199 in 389-ds-base was insufficient to cover all scenarios. In certain...
Moderate
Unreviewed
CVE-2024-8445
was published
Sep 5, 2024
SSRF in Sydent due to missing validation of hostnames
Moderate
CVE-2021-29431
was published
for
matrix-sydent
(pip)
Apr 19, 2021
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Moderate
CVE-2021-21393
was published
for
matrix-synapse
(pip)
Apr 13, 2021
mangadex-downloader vulnerable to unauthorized file reading
Moderate
CVE-2022-36082
was published
for
mangadex-downloader
(pip)
Sep 16, 2022
A Improper Input Validation issue affecting the v2_sdk_service running on a set of DJI drone...
Moderate
Unreviewed
CVE-2023-51456
was published
Apr 2, 2024
Improper input validation in Zoom Desktop Client for Windows before 5.15.5 may allow an...
Moderate
Unreviewed
CVE-2023-39209
was published
Aug 9, 2023
HashiCorp Vault Improper Input Validation vulnerability
Moderate
CVE-2023-4680
was published
for
github.com/hashicorp/vault
(Go)
Sep 15, 2023
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow...
Moderate
Unreviewed
CVE-2023-4393
was published
Oct 30, 2023
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Moderate
CVE-2021-21394
was published
for
matrix-synapse
(pip)
Apr 13, 2021
Malicious users could abuse Sydent to control the content of invitation emails
Moderate
CVE-2021-29432
was published
for
matrix-sydent
(pip)
Apr 19, 2021
Sydent DoS (via resource exhaustion) due to improper input validation
Moderate
CVE-2021-29433
was published
for
matrix-sydent
(pip)
Apr 16, 2021
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
Moderate
CVE-2023-32323
was published
for
matrix-synapse
(pip)
May 24, 2023
Contao affected by insert tag injection via canonical URL
Moderate
CVE-2024-45612
was published
for
contao/core-bundle
(Composer)
Sep 17, 2024
httplib2 incorrectly checks SSL certificate
Moderate
CVE-2013-2037
was published
for
httplib2
(pip)
May 14, 2022
Improper Input Validation vulnerability in Hitachi Energy MicroSCADA X SYS600 while reading a...
Moderate
Unreviewed
CVE-2022-1778
was published
Sep 15, 2022
In camera middleware, there is a possible out of bounds write due to a missing input validation....
Moderate
Unreviewed
CVE-2023-32827
was published
Oct 2, 2023
In camera middleware, there is a possible out of bounds write due to a missing input validation....
Moderate
Unreviewed
CVE-2023-32826
was published
Oct 2, 2023
ProTip!
Advisories are also available from the
GraphQL API