GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,413
Erlang
29
GitHub Actions
16
Go
1,653
Maven
4,915
npm
3,442
NuGet
594
pip
2,832
Pub
10
RubyGems
823
Rust
763
Swift
34
Unreviewed advisories
All unreviewed
5,000+
28 advisories
Filter by severity
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open...
Moderate
Unreviewed
CVE-2013-1636
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Foundation 2013 Gold and SP1 and...
Low
Unreviewed
CVE-2015-1636
was published
May 14, 2022
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote...
High
Unreviewed
CVE-2013-2328
was published
May 13, 2022
Integer overflow in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR 10.x before...
High
Unreviewed
CVE-2012-5835
was published
May 13, 2022
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0,...
High
Unreviewed
CVE-2012-5842
was published
May 13, 2022
Heap-based buffer overflow in the gfxShapedWord::CompressedGlyph::IsClusterStart function in...
High
Unreviewed
CVE-2012-5839
was published
May 13, 2022
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0,...
Moderate
Unreviewed
CVE-2012-5841
was published
May 13, 2022
Heap-based buffer overflow in the image::RasterImage::DrawFrameTo function in Mozilla Firefox...
High
Unreviewed
CVE-2012-4202
was published
May 13, 2022
The texImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0, Firefox ESR...
High
Unreviewed
CVE-2012-5833
was published
May 13, 2022
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox...
High
Unreviewed
CVE-2012-5840
was published
May 13, 2022
Use-after-free vulnerability in the nsPlaintextEditor::FireClipboardEvent function in Mozilla...
High
Unreviewed
CVE-2012-4215
was published
May 13, 2022
The XrayWrapper implementation in Mozilla Firefox before 17.0, Thunderbird before 17.0, and...
Moderate
Unreviewed
CVE-2012-4208
was published
May 13, 2022
The str_unescape function in the JavaScript engine in Mozilla Firefox before 17.0, Thunderbird...
High
Unreviewed
CVE-2012-4204
was published
May 13, 2022
Use-after-free vulnerability in the nsEditor::FindNextLeafNode function in Mozilla Firefox before...
High
Unreviewed
CVE-2012-4213
was published
May 13, 2022
Use-after-free vulnerability in the nsViewManager::ProcessPendingUpdates function in Mozilla...
High
Unreviewed
CVE-2012-4217
was published
May 13, 2022
Mozilla Firefox before 17.0, Thunderbird before 17.0, and SeaMonkey before 2.14 allow remote...
High
Unreviewed
CVE-2012-5836
was published
May 13, 2022
The copyTexImage2D implementation in the WebGL subsystem in Mozilla Firefox before 17.0,...
High
Unreviewed
CVE-2012-5838
was published
May 13, 2022
Use-after-free vulnerability in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11,...
High
Unreviewed
CVE-2012-5830
was published
May 13, 2022
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 17.0,...
High
Unreviewed
CVE-2012-5843
was published
May 13, 2022
The HZ-GB-2312 character-set implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x...
Moderate
Unreviewed
CVE-2012-4207
was published
May 13, 2022
Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0,...
Moderate
Unreviewed
CVE-2012-4209
was published
May 13, 2022
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox...
High
Unreviewed
CVE-2012-4214
was published
May 13, 2022
Use-after-free vulnerability in the gfxFont::GetFontEntry function in Mozilla Firefox before 17.0...
High
Unreviewed
CVE-2012-4216
was published
May 13, 2022
The evalInSandbox implementation in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11,...
Moderate
Unreviewed
CVE-2012-4201
was published
May 13, 2022
Heap-based buffer overflow in the nsWindow::OnExposeEvent function in Mozilla Firefox before 17.0...
High
Unreviewed
CVE-2012-5829
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API