GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
159,178 advisories
Filter by severity
IBM Sterling Integrator 5.1 before 5010004_8 and Sterling B2B Integrator 5.2 before 5020500_9...
Moderate
Unreviewed
CVE-2015-5019
was published
May 17, 2022
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via...
Moderate
Unreviewed
CVE-2014-6497
was published
May 17, 2022
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10...
Moderate
Unreviewed
CVE-2014-6534
was published
May 17, 2022
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute...
Moderate
Unreviewed
CVE-2015-0682
was published
May 17, 2022
Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605...
Moderate
Unreviewed
CVE-2015-3967
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics...
Moderate
Unreviewed
CVE-2015-5444
was published
May 17, 2022
Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7...
Moderate
Unreviewed
CVE-2014-6522
was published
May 17, 2022
SQL injection vulnerability in Network Applied Communication Laboratory Pref Shimane CMS 2.x...
Moderate
Unreviewed
CVE-2015-5659
was published
May 17, 2022
Multiple directory traversal vulnerabilities in the integrated web server in Siemens SINEMA...
Moderate
Unreviewed
CVE-2014-2732
was published
May 17, 2022
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x...
Moderate
Unreviewed
CVE-2014-0471
was published
May 17, 2022
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web...
Moderate
Unreviewed
CVE-2014-7243
was published
May 17, 2022
EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which...
Moderate
Unreviewed
CVE-2015-6034
was published
May 17, 2022
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3,...
Moderate
Unreviewed
CVE-2014-6537
was published
May 17, 2022
The Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 allows...
Moderate
Unreviewed
CVE-2011-2221
was published
May 17, 2022
X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a...
Moderate
Unreviewed
CVE-2013-1996
was published
May 17, 2022
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote...
Moderate
Unreviewed
CVE-2015-1165
was published
May 17, 2022
Session fixation vulnerability in IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1...
Moderate
Unreviewed
CVE-2015-2029
was published
May 17, 2022
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account...
Moderate
Unreviewed
CVE-2015-2030
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to...
Moderate
Unreviewed
CVE-2015-5651
was published
May 17, 2022
The CPU Software in Apple OS X before 10.10.2 allows physically proximate attackers to modify...
Moderate
Unreviewed
CVE-2014-4498
was published
May 17, 2022
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 does not set the secure...
Moderate
Unreviewed
CVE-2015-2025
was published
May 17, 2022
IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.9 FP009, and 7.6.0 before 7...
Moderate
Unreviewed
CVE-2015-4966
was published
May 17, 2022
The user interface in WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x...
Moderate
Unreviewed
CVE-2015-1084
was published
May 17, 2022
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3,...
Moderate
Unreviewed
CVE-2014-4294
was published
May 17, 2022
The Groupon Redemptions application for Android does not verify that the server hostname matches...
Moderate
Unreviewed
CVE-2012-5809
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API