GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,101
Maven
5,000+
npm
3,764
NuGet
679
pip
3,451
Pub
12
RubyGems
892
Rust
885
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
4,295 advisories
Filter by severity
Memory corruption due to improper check to return error when user application requests memory...
High
Unreviewed
CVE-2020-11261
was published
May 24, 2022
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the...
High
Unreviewed
CVE-2023-22952
was published
Jan 11, 2023
A memory corruption issue was addressed with improved input validation. This issue is fixed in...
High
Unreviewed
CVE-2020-27930
was published
May 24, 2022
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur...
High
Unreviewed
CVE-2021-30713
was published
May 24, 2022
Windows MSHTML Platform Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-30040
was published
May 14, 2024
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow...
High
Unreviewed
CVE-2018-0296
was published
May 13, 2022
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco...
High
Unreviewed
CVE-2018-0172
was published
May 13, 2022
A packet processing mechanism in Palo Alto Networks PAN-OS software enables a remote attacker to...
High
Unreviewed
CVE-2024-3385
was published
Apr 10, 2024
An unauthenticated remote attacker can write memory out of bounds due to improper input...
High
Unreviewed
CVE-2024-26001
was published
Mar 12, 2024
An unauthenticated remote attacker can perform a command injection in the OCPP Service with...
High
Unreviewed
CVE-2024-25998
was published
Mar 12, 2024
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics...
High
Unreviewed
CVE-2015-2291
was published
May 17, 2022
A Server-Side Request Forgery (SSRF) vulnerability has been identified in the Web Services...
High
Unreviewed
CVE-2023-50733
was published
Jan 22, 2025
Dell Repository Manager, versions prior to 3.4.5, contains a Path Traversal vulnerability in API...
High
Unreviewed
CVE-2024-28976
was published
Apr 24, 2024
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003...
High
Unreviewed
CVE-2012-0180
was published
May 4, 2022
SBE.dll in the Stream Buffer Engine in Windows Media Player and Windows Media Center in Microsoft...
High
Unreviewed
CVE-2011-0042
was published
May 3, 2022
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and...
High
Unreviewed
CVE-2009-0082
was published
May 2, 2022
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3...
High
Unreviewed
CVE-2008-2374
was published
May 1, 2022
Memory corruption when the channel ID passed by user is not validated and further used.
High
Unreviewed
CVE-2024-21476
was published
May 6, 2024
Microsoft SharePoint Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2025-21344
was published
Jan 14, 2025
Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21370
was published
Jan 14, 2025
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21235
was published
Jan 14, 2025
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2025-21234
was published
Jan 14, 2025
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
High
Unreviewed
CVE-2025-21230
was published
Jan 14, 2025
An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a...
High
Unreviewed
CVE-2023-51931
was published
Feb 16, 2024
ProTip!
Advisories are also available from the
GraphQL API