GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
Inconsistent documentation in Apache Tomcat
Moderate
CVE-2017-15706
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to...
Moderate
Unreviewed
CVE-2016-8635
was published
May 13, 2022
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS...
Moderate
Unreviewed
CVE-2017-12303
was published
May 13, 2022
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4...
High
Unreviewed
CVE-2017-15091
was published
May 13, 2022
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus...
Moderate
Unreviewed
CVE-2017-6032
was published
May 13, 2022
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA)...
Critical
Unreviewed
CVE-2018-0268
was published
May 13, 2022
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad...
Moderate
Unreviewed
CVE-2018-16857
was published
May 13, 2022
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9,...
High
Unreviewed
CVE-2018-1243
was published
May 13, 2022
IBM Security Access Manager for Web could allow a remote attacker to obtain sensitive information...
High
Unreviewed
CVE-2016-3017
was published
May 13, 2022
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
Moderate
Unreviewed
CVE-2021-42017
was published
Mar 9, 2022
Improperly Implemented Security Check for Standard in org.springframework:spring-core
Critical
CVE-2018-1275
was published
for
org.springframework:spring-core
(Maven)
Oct 17, 2018
Spring Framework allows applications to expose STOMP over WebSocket endpoints
Critical
CVE-2018-1270
was published
for
org.springframework:spring-core
(Maven)
Oct 17, 2018
Ansible apt_key module does not properly verify key fingerprint
High
CVE-2016-8614
was published
for
ansible
(pip)
Oct 10, 2018
In marshmallow library the schema "only" option treats an empty list as implying no "only" option
Moderate
CVE-2018-17175
was published
for
marshmallow
(pip)
Oct 10, 2018
ProTip!
Advisories are also available from the
GraphQL API