GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
362 advisories
Filter by severity
Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This...
Moderate
Unreviewed
CVE-2024-11159
was published
Nov 13, 2024
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not...
Moderate
Unreviewed
CVE-2020-10369
was published
Nov 11, 2024
Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not...
Moderate
Unreviewed
CVE-2020-10367
was published
Nov 11, 2024
An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through...
Moderate
Unreviewed
CVE-2023-37305
was published
Jun 30, 2023
vantage6 vulnerable to Observable Response Discrepancy
Moderate
CVE-2022-39228
was published
for
vantage6
(pip)
Feb 28, 2023
A vulnerability in Cisco Integrated Management Controller could allow an unauthenticated,...
Moderate
Unreviewed
CVE-2020-26062
was published
Nov 18, 2024
A vulnerability, which was classified as problematic, was found in spa-cartcms 1.9.0.6. Affected...
Moderate
Unreviewed
CVE-2024-6129
was published
Jun 18, 2024
A vulnerability was found in nasirkhan Laravel Starter up to 11.8.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-6056
was published
Jun 17, 2024
IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to...
Moderate
Unreviewed
CVE-2024-41741
was published
Nov 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
x86: fix user address...
Moderate
Unreviewed
CVE-2024-50102
was published
Nov 5, 2024
wolfSSL SP Math All RSA implementation is vulnerable to the Marvin Attack, new variation of a...
Moderate
Unreviewed
CVE-2023-6935
was published
Feb 10, 2024
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported...
Moderate
Unreviewed
CVE-2024-21233
was published
Oct 15, 2024
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business...
Moderate
Unreviewed
CVE-2024-21206
was published
Oct 15, 2024
By checking the result of calls to `window.open` with specifically set protocol handlers, an...
Moderate
Unreviewed
CVE-2024-9398
was published
Oct 1, 2024
This issue occurs during password recovery, where a difference in messages could allow an...
Moderate
Unreviewed
CVE-2024-2464
was published
Mar 21, 2024
Django allows enumeration of user e-mail addresses
Moderate
CVE-2024-45231
was published
for
Django
(pip)
Oct 8, 2024
In Logpoint before 7.4.0, an attacker can enumerate a valid list of usernames by using publicly...
Moderate
Unreviewed
CVE-2024-30176
was published
May 1, 2024
Inappropriate implementation in Paint in Google Chrome prior to 98.0.4758.80 allowed a remote...
Moderate
Unreviewed
CVE-2022-4025
was published
Jan 3, 2023
A privacy issue was addressed by moving sensitive data to a more secure location. This issue is...
Moderate
Unreviewed
CVE-2024-27839
was published
May 14, 2024
Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent...
Moderate
Unreviewed
CVE-2024-50383
was published
Oct 23, 2024
Botan before 3.6.0, when certain LLVM versions are used, has compiler-induced secret-dependent...
Moderate
Unreviewed
CVE-2024-50382
was published
Oct 23, 2024
Accounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware...
Moderate
Unreviewed
CVE-2024-48644
was published
Oct 23, 2024
In the Linux kernel, the following vulnerability has been resolved:
icmp: change the order of...
Moderate
Unreviewed
CVE-2024-47678
was published
Oct 21, 2024
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of...
Moderate
Unreviewed
CVE-2024-0564
was published
Jan 30, 2024
Gradio performs a non-constant-time comparison when comparing hashes
Moderate
CVE-2024-47869
was published
for
gradio
(pip)
Oct 10, 2024
ProTip!
Advisories are also available from the
GraphQL API