GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,413
Erlang
28
GitHub Actions
16
Go
1,651
Maven
4,914
npm
3,437
NuGet
594
pip
2,782
Pub
10
RubyGems
822
Rust
760
Swift
34
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
java-xmlbuilder vulnerable to XML External Entity Reference
Critical
CVE-2014-125087
was published
for
com.jamesmurty.utils:java-xmlbuilder
(Maven)
Feb 19, 2023
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, does not properly validate...
Moderate
Unreviewed
CVE-2014-1297
was published
May 17, 2022
The storageVolUpload function in storage/storage_driver.c in libvirt before 1.2.11 does not check...
Low
Unreviewed
CVE-2014-8135
was published
May 17, 2022
EMC Documentum Web Development Kit (WDK) before 6.8 allows remote attackers to conduct frame...
Moderate
Unreviewed
CVE-2014-4638
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum Web Development Kit (WDK)...
Moderate
Unreviewed
CVE-2014-4635
was published
May 17, 2022
Open redirect vulnerability in EMC Documentum Web Development Kit (WDK) before 6.8 allows remote...
Moderate
Unreviewed
CVE-2014-4637
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability in EMC Documentum Web Development Kit (WDK)...
Moderate
Unreviewed
CVE-2014-4636
was published
May 17, 2022
Unspecified vulnerability in Apple Safari 7.0.2 on OS X allows remote attackers to execute...
High
Unreviewed
CVE-2014-1300
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1299
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1302
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1298
was published
May 17, 2022
Heap-based buffer overflow in Apple Safari 7.0.2 allows remote attackers to execute arbitrary...
High
Unreviewed
CVE-2014-1303
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1304
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1307
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1309
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1305
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1308
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1310
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1313
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1312
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1311
was published
May 17, 2022
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to...
Moderate
Unreviewed
CVE-2014-1301
was published
May 17, 2022
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when...
Moderate
Unreviewed
CVE-2013-4475
was published
May 17, 2022
Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc...
High
Unreviewed
CVE-2013-4408
was published
May 17, 2022
Use-after-free vulnerability in the AttributeSetter function in bindings/templates/attributes.cpp...
High
Unreviewed
CVE-2014-1713
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API