GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,413
Erlang
28
GitHub Actions
16
Go
1,651
Maven
4,914
npm
3,437
NuGet
594
pip
2,782
Pub
10
RubyGems
822
Rust
760
Swift
34
Unreviewed advisories
All unreviewed
5,000+
18 advisories
Filter by severity
parser.c in libxml2 before 2.9.0, as used in Google Chrome before 28.0.1500.71 and other products...
Moderate
Unreviewed
CVE-2013-2877
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with...
Moderate
Unreviewed
CVE-2014-2249
was published
May 17, 2022
Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x,...
Moderate
Unreviewed
CVE-2013-2099
was published
May 17, 2022
Multiple integer overflows in the (1) GC_generic_malloc and (2) calloc functions in malloc.c, and...
Moderate
Unreviewed
CVE-2012-2673
was published
May 17, 2022
Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote attackers to...
High
Unreviewed
CVE-2013-2871
was published
May 17, 2022
core/rendering/svg/SVGInlineTextBox.cpp in the SVG implementation in Blink, as used in Google...
Moderate
Unreviewed
CVE-2013-2875
was published
May 17, 2022
Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a...
High
Unreviewed
CVE-2014-5074
was published
May 14, 2022
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information...
Moderate
Unreviewed
CVE-2014-8889
was published
May 14, 2022
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7...
Low
Unreviewed
CVE-2013-1500
was published
May 14, 2022
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0...
Moderate
Unreviewed
CVE-2014-2247
was published
May 13, 2022
The random-number generator on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0...
High
Unreviewed
CVE-2014-2251
was published
May 13, 2022
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC...
Moderate
Unreviewed
CVE-2014-2248
was published
May 13, 2022
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500...
Moderate
Unreviewed
CVE-2014-2246
was published
May 13, 2022
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to...
High
Unreviewed
CVE-2014-2255
was published
May 13, 2022
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to...
High
Unreviewed
CVE-2014-2257
was published
May 13, 2022
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to...
Moderate
Unreviewed
CVE-2014-2253
was published
May 13, 2022
Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allow remote attackers to...
High
Unreviewed
CVE-2014-2259
was published
May 13, 2022
Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of...
Moderate
Unreviewed
CVE-2014-1500
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API