GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
4,694 advisories
Filter by severity
Input verification vulnerability in the log module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-27896
was published
Apr 8, 2024
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an...
High
Unreviewed
CVE-2019-12687
was published
May 24, 2022
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an...
High
Unreviewed
CVE-2019-12688
was published
May 24, 2022
A vulnerability in the web UI of Cisco Firepower Management Center (FMC) Software could allow an...
High
Unreviewed
CVE-2020-3302
was published
May 24, 2022
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows...
High
Unreviewed
CVE-2016-6433
was published
May 13, 2022
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
High
Unreviewed
CVE-2017-15832
was published
Nov 26, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request
High
CVE-2024-0793
was published
for
k8s.io/kubernetes
(Go)
Nov 17, 2024
Apache Airflow Drill Provider vulnerable to improper input validation
High
CVE-2023-28707
was published
for
apache-airflow-providers-apache-drill
(pip)
Apr 7, 2023
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
High
CVE-2023-39553
was published
for
apache-airflow-providers-apache-drill
(pip)
Aug 11, 2023
Tornado CRLF injection vulnerability
High
CVE-2012-2374
was published
for
tornado
(pip)
May 17, 2022
Transifex command-line client has improper certificate validation
High
CVE-2013-7110
was published
for
transifex-client
(pip)
May 17, 2022
Apache Syncope Improper Input Validation vulnerability
High
CVE-2024-38503
was published
for
org.apache.syncope.client.idrepo:syncope-client-idrepo-common-ui
(Maven)
Jul 22, 2024
Arbitrary File Creation in opencart
High
CVE-2024-21519
was published
for
opencart/opencart
(Composer)
Jun 22, 2024
Lightning Network Daemon (LND)'s onion processing logic leads to a denial of service
High
CVE-2024-38359
was published
for
github.com/lightningnetwork/lnd
(Go)
Jun 20, 2024
Grafana Email addresses and usernames can not be trusted
High
CVE-2022-39306
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
Apache Airflow Improper Input Validation vulnerability
High
CVE-2023-36543
was published
for
apache-airflow
(pip)
Jul 12, 2023
Apache Airflow Improper Input Validation vulnerability
High
CVE-2023-22888
was published
for
apache-airflow
(pip)
Jul 12, 2023
CairoSVG improperly processes SVG files loaded from external resources
High
CVE-2023-27586
was published
for
CairoSVG
(pip)
Mar 20, 2023
Ansible password prompts could expose passwords
High
CVE-2019-10206
was published
for
ansible
(pip)
May 24, 2022
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
High
CVE-2019-14905
was published
for
ansible
(pip)
Apr 20, 2021
Improper query string handling in Django
High
CVE-2010-4534
was published
for
Django
(pip)
Jul 23, 2018
The WinVerifyTrust function in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows...
High
Unreviewed
CVE-2013-3900
was published
May 3, 2022
Valid Host header field can cause Apache Traffic Server to crash on some platforms.
This issue...
High
Unreviewed
CVE-2024-50305
was published
Nov 14, 2024
ProTip!
Advisories are also available from the
GraphQL API