GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,972
Erlang
29
GitHub Actions
16
Go
1,762
Maven
4,983
npm
3,518
NuGet
609
pip
3,094
Pub
10
RubyGems
833
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
10,676 advisories
Filter by severity
A privacy issue was addressed with improved handling of temporary files. This issue is fixed in...
Low
Unreviewed
CVE-2024-23217
was published
Jan 23, 2024
This vulnerability potentially allows files on a PaperCut NG/MF server to be exposed using a...
Low
Unreviewed
CVE-2024-1221
was published
Mar 14, 2024
Insertion of sensitive information into log file for some Intel(R) Local Manageability Service...
Low
Unreviewed
CVE-2023-27502
was published
Mar 14, 2024
LangChain directory traversal vulnerability
Low
CVE-2024-28088
was published
for
langchain
(pip)
Mar 4, 2024
A vulnerability has been found in Surya2Developer Hostel Management Service 1.0 and classified as...
Low
Unreviewed
CVE-2024-2482
was published
Mar 15, 2024
Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of...
Low
Unreviewed
CVE-2024-28053
was published
Mar 15, 2024
Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the...
Low
Unreviewed
CVE-2024-24975
was published
Mar 15, 2024
fgr Vulnerable to Insecure Default Variable Initialization
Low
GHSA-879p-8gw4-mcpw
was published
for
fgr
(pip)
Mar 15, 2024
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as problematic, was found...
Low
Unreviewed
CVE-2024-2567
was published
Mar 17, 2024
Adobe Experience Manager versions 6.5.19 and earlier are affected by a stored Cross-Site...
Low
Unreviewed
CVE-2024-26051
was published
Mar 18, 2024
Mattermost Jira Plugin vulnerable to Cross-Site Request Forgery
Low
CVE-2024-23319
was published
for
github.com/mattermost/mattermost-plugin-jira
(Go)
Feb 9, 2024
[TagAwareCipher] - Decryption Failure (Regex Match)
Low
CVE-2024-28864
was published
for
ilicmiljan/secure-props
(Composer)
Mar 18, 2024
Dynamic Variable Evaluation in qiskit-ibm-runtime
Low
GHSA-cq96-9974-v8hm
was published
for
qiskit-ibm-runtime
(pip)
Mar 20, 2024
Missing Cryptographic Step in OWASP Enterprise Security API for Java
Low
CVE-2013-5679
was published
for
org.owasp.esapi:esapi
(Maven)
May 17, 2022
** DISPUTED ** Bludit 3.10.0 allows Editor or Author roles to insert malicious JavaScript on the...
Low
Unreviewed
CVE-2020-8812
was published
May 24, 2022
gss_mech_free in net/sunrpc/auth_gss/gss_mech_switch.c in the rpcsec_gss_krb5 implementation in...
Low
Unreviewed
CVE-2020-12656
was published
May 24, 2022
** DISPUTED ** GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown...
Low
Unreviewed
CVE-2021-3349
was published
May 24, 2022
Cross-site Scripting in actionpack
Low
CVE-2022-3704
was published
for
actionpack
(RubyGems)
Oct 27, 2022
•
withdrawn
Crash when processing crafted TIFF files
Low
CVE-2023-36308
was published
for
github.com/disintegration/imaging
(Go)
Sep 5, 2023
Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle...
Low
Unreviewed
CVE-2024-1742
was published
Mar 22, 2024
IBM Security Verify Directory 10.0.0 could allow a remote attacker to obtain sensitive...
Low
Unreviewed
CVE-2022-32756
was published
Mar 22, 2024
Kaspersky has fixed a security issue in Kaspersky Password Manager (KPM) for Windows that allowed...
Low
Unreviewed
CVE-2023-23349
was published
Mar 22, 2024
Regular Expression Denial of Service in debug
Low
CVE-2017-16137
was published
for
debug
(npm)
Aug 9, 2018
Unauthenticated views may expose information to anonymous users
Low
CVE-2024-29199
was published
for
nautobot
(pip)
Mar 26, 2024
phpMyFAQ Path Traversal in Attachments
Low
CVE-2024-29196
was published
for
phpmyfaq/phpmyfaq
(Composer)
Mar 25, 2024
ProTip!
Advisories are also available from the
GraphQL API