GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
10,785 advisories
Filter by severity
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input...
Moderate
Unreviewed
CVE-2024-45761
was published
Dec 9, 2024
Insufficient validation of filenames against control characters in Apache Subversion repositories...
Low
Unreviewed
CVE-2024-46901
was published
Dec 9, 2024
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified...
Moderate
Unreviewed
CVE-2024-12355
was published
Dec 9, 2024
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone...
Moderate
Unreviewed
CVE-2024-12353
was published
Dec 9, 2024
sigstore-java has a vulnerability with bundle verification
Low
CVE-2024-54140
was published
for
dev.sigstore:sigstore-java
(Maven)
Dec 5, 2024
Improper Input Validation vulnerability in RestApp Inc. Online Ordering System allows Integer...
Moderate
Unreviewed
CVE-2024-7488
was published
Dec 4, 2024
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability...
Moderate
Unreviewed
CVE-2024-12138
was published
Dec 4, 2024
An improper input validation vulnerability leads to device crashes in certain ASUS router models....
Moderate
Unreviewed
CVE-2024-11985
was published
Dec 4, 2024
Synapse allows a a malformed invite to break the invitee's `/sync`
High
CVE-2024-52815
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Memory corruption while processing API calls to NPU with invalid input.
High
Unreviewed
CVE-2024-43052
was published
Dec 2, 2024
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API...
Moderate
Unreviewed
CVE-2024-52337
was published
Nov 26, 2024
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon...
Low
Unreviewed
CVE-2024-22117
was published
Nov 26, 2024
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
High
Unreviewed
CVE-2017-15832
was published
Nov 26, 2024
A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been...
Moderate
Unreviewed
CVE-2024-11662
was published
Nov 25, 2024
Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion...
Moderate
Unreviewed
CVE-2024-9257
was published
Nov 22, 2024
Possible out of bound access in audio module due to lack of validation of user provided input.
Moderate
Unreviewed
CVE-2021-30299
was published
Nov 22, 2024
django Filer Unrestricted Upload of File with Dangerous Type
Moderate
CVE-2024-11404
was published
for
django-filer
(pip)
Nov 20, 2024
Improper input validation in some Zoom Apps before version 6.2.0 may allow an unauthenticated...
Moderate
Unreviewed
CVE-2024-45422
was published
Nov 19, 2024
A vulnerability in the CLI of Cisco SD-WAN vManage Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2021-1462
was published
Nov 18, 2024
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could...
Moderate
Unreviewed
CVE-2021-1465
was published
Nov 18, 2024
A vulnerability in a certain REST API endpoint of Cisco Data Center Network Manager (DCNM)...
Moderate
Unreviewed
CVE-2020-3538
was published
Nov 18, 2024
Kubernetes Nil pointer dereference in KCM after v1 HPA patch request
High
CVE-2024-0793
was published
for
k8s.io/kubernetes
(Go)
Nov 17, 2024
A vulnerability in Cisco SD-WAN vManage Software could allow an authenticated, remote...
Moderate
Unreviewed
CVE-2021-1464
was published
Nov 15, 2024
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could...
Moderate
Unreviewed
CVE-2021-1470
was published
Nov 15, 2024
A vulnerability in the vDaemon service of Cisco SD-WAN vManage Software could allow an...
Moderate
Unreviewed
CVE-2021-1466
was published
Nov 15, 2024
ProTip!
Advisories are also available from the
GraphQL API