GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,736
Erlang
25
GitHub Actions
16
Go
1,448
Maven
4,651
npm
3,304
NuGet
563
pip
2,379
Pub
8
RubyGems
791
Rust
725
Swift
33
Unreviewed advisories
All unreviewed
5,000+
16,479 advisories
Filter by severity
.NET Information Disclosure Vulnerability
Critical
GHSA-vh55-786g-wjwj
was published
for
Microsoft.AspNetCore.App.Runtime.linux-arm
(NuGet)
Feb 3, 2024
Zmarkdown Server-Side Request Forgery (SSRF) in remark-download-images
Moderate
GHSA-mf74-qq7w-6j7v
was published
for
zmarkdown
(npm)
Feb 3, 2024
Local File Inclusion vulnerability in zmarkdown
Low
GHSA-mq6v-w35g-3c97
was published
for
zmarkdown
(npm)
Feb 3, 2024
Nervos CKB Permit load cell data from memory
Moderate
GHSA-29c2-65rj-h343
was published
for
ckb
(Rust)
Feb 3, 2024
Nervos CKB Pool does not remove the conflicting transactions from the statistics
Moderate
GHSA-h4c3-5275-vrmg
was published
for
ckb
(Rust)
Feb 3, 2024
Use after free in libpulse-binding
High
GHSA-f56g-chqp-22m9
was published
for
libpulse-binding
(Rust)
Feb 3, 2024
github-slug-action use of `set-env` Runner commands which are processed via stdout
Moderate
GHSA-7f32-hm4h-w77q
was published
for
rlespinasse/github-slug-action
(GitHub Actions)
Feb 3, 2024
Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic result
Critical
GHSA-q73f-w3h7-7wcc
was published
for
ckb
(Rust)
Feb 3, 2024
Nervos CKB Snappy decompress length can be very large and causes out of memory error
High
GHSA-3gjh-29fv-8hr6
was published
for
ckb
(Rust)
Feb 3, 2024
Nervos CKB Panic on malformed input
High
GHSA-wjxc-pjx9-4wvm
was published
for
ckb
(Rust)
Feb 3, 2024
Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only
Low
GHSA-vjg6-93fv-qv64
was published
for
go.etcd.io/etcd
(Go)
Feb 3, 2024
Etcd embed auto compaction retention negative value causing a compaction loop or a crash
Low
GHSA-pm3m-32r3-7mfh
was published
for
go.etcd.io/etcd
(Go)
Feb 3, 2024
Etcd Gateway TLS endpoint validation only confirms TCP reachability
Moderate
GHSA-j86v-2vjr-fg8f
was published
for
go.etcd.io/etcd
(Go)
Feb 3, 2024
Etcd pkg Insecure ciphers are allowed by default
Low
GHSA-5x4g-q5rc-36jp
was published
for
go.etcd.io/etcd/client/pkg/v3
(Go)
Feb 3, 2024
Nervos CKB node panics when processing a block which parent timestamp is too new
High
GHSA-hjqq-29pw-96wj
was published
for
ckb
(Rust)
Feb 2, 2024
Nervos CKB BlockTimeTooNew should not be considered as invalid block
Moderate
GHSA-r9rv-9mh8-pxf4
was published
for
ckb
(Rust)
Feb 2, 2024
Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IP
Low
GHSA-pr39-8257-fxc2
was published
for
ckb
(Rust)
Feb 2, 2024
PowerShell is subject to remote code execution vulnerability
High
GHSA-jcmq-5rrv-j2g4
was published
for
PowerShell
(NuGet)
Feb 2, 2024
Nervos CKB Unaligned Pointer Dereference
Moderate
GHSA-q669-2vfg-cxcg
was published
for
ckb
(Rust)
Feb 2, 2024
PHPMailer Local file inclusion
Moderate
CVE-2006-5734
was published
for
phpmailer/phpmailer
(Composer)
Feb 2, 2024
PHPMailer Shell command injection
High
CVE-2007-3215
was published
for
phpmailer/phpmailer
(Composer)
Feb 2, 2024
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
Moderate
CVE-2023-51838
was published
for
meshcentral
(npm)
Feb 2, 2024
Talos Linux ships runc vulnerable to the escape to the host attack
High
GHSA-g5p6-327m-3fxx
was published
for
github.com/siderolabs/talos
(Go)
Feb 2, 2024
Vyper's external calls can overflow return data to return input buffer
Low
CVE-2024-24560
was published
for
vyper
(pip)
Feb 2, 2024
ProTip!
Advisories are also available from the
GraphQL API