GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
11,639 advisories
Filter by severity
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could...
Critical
Unreviewed
CVE-2019-1971
was published
May 24, 2022
A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Moderate
Unreviewed
CVE-2019-1952
was published
May 24, 2022
Evernote before 7.13 GA on macOS allows code execution because the com.apple.quarantine attribute...
Moderate
Unreviewed
CVE-2019-17051
was published
May 24, 2022
NVIDIA Windows GPU Display Driver (all versions) contains a vulnerability in the kernel mode...
Moderate
Unreviewed
CVE-2019-5686
was published
May 24, 2022
IBM WebSphere MQ V7.1, 7.5, IBM MQ V8, IBM MQ V9.0LTS, IBM MQ V9.1 LTS, and IBM MQ V9.1 CD are...
Moderate
Unreviewed
CVE-2019-4261
was published
May 24, 2022
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in...
Moderate
Unreviewed
CVE-2022-28199
was published
Sep 2, 2022
When a user opens a manipulated Tagged Image File Format (.tiff, 2d.x3d)) received from untrusted...
Moderate
Unreviewed
CVE-2022-22537
was published
Feb 11, 2022
When a user opens a manipulated JPEG file format (.jpg, 2d.x3d) received from untrusted sources...
Moderate
Unreviewed
CVE-2022-22539
was published
Feb 11, 2022
IBM MQ 9.1.0.0, 9.1.0.1, 9.1.1, and 9.1.0.2 is vulnerable to a denial of service due to a local...
Moderate
Unreviewed
CVE-2019-4049
was published
May 24, 2022
IBM API Connect 2018.1 through 2018.4.1.6 developer portal could allow an unauthorized user to...
High
Unreviewed
CVE-2019-4402
was published
May 24, 2022
While rendering the layout background, Error status check is not caught properly and also...
Moderate
Unreviewed
CVE-2019-2241
was published
May 24, 2022
GNU binutils gold gold v1.11-v1.16 (GNU binutils v2.21-v2.31.1) is affected by: Improper Input...
Moderate
Unreviewed
CVE-2019-1010204
was published
May 24, 2022
The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input...
Critical
Unreviewed
CVE-2019-1010245
was published
May 24, 2022
When a user opens a manipulated Adobe Illustrator file format (.ai, ai.x3d) received from...
Moderate
Unreviewed
CVE-2022-22538
was published
Feb 11, 2022
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012...
Moderate
Unreviewed
CVE-2022-35668
was published
Aug 12, 2022
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Moderate
Unreviewed
CVE-2019-1961
was published
May 24, 2022
A vulnerability in the web-based management interface of Cisco Webex Meetings Server Software...
Moderate
Unreviewed
CVE-2019-1954
was published
May 24, 2022
Sanity checks are missing in layout which can lead to SUI Corruption or can lead to Denial of...
Moderate
Unreviewed
CVE-2019-2239
was published
May 24, 2022
In several JetBrains IntelliJ IDEA versions, a Spring Boot run configuration with the default...
Critical
Unreviewed
CVE-2019-9186
was published
May 24, 2022
Apache Karaf vulnerable to potential code injection
Critical
CVE-2022-40145
was published
for
org.apache.karaf:apache-karaf
(Maven)
Dec 21, 2022
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed...
Moderate
Unreviewed
CVE-2019-5838
was published
May 24, 2022
An issue where a provided address with access_ok() is not checked was discovered in...
High
Unreviewed
CVE-2018-20669
was published
May 13, 2022
Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp...
Moderate
Unreviewed
CVE-2019-3970
was published
May 24, 2022
LibreOffice has a feature where documents can specify that pre-installed scripts can be executed...
Critical
Unreviewed
CVE-2019-9848
was published
May 24, 2022
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read...
Moderate
Unreviewed
CVE-2023-20527
was published
Jan 11, 2023
ProTip!
Advisories are also available from the
GraphQL API