GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
21 advisories
Filter by severity
An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid...
High
Unreviewed
CVE-2019-11412
was published
May 24, 2022
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing...
High
Unreviewed
CVE-2020-25603
was published
May 24, 2022
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left...
High
Unreviewed
CVE-2020-36277
was published
May 24, 2022
In updateCapabilities of ConnectivityService.java, there is a possible incorrect network state...
High
Unreviewed
CVE-2021-0517
was published
May 24, 2022
A vulnerability in IPv6 traffic processing of Cisco IOS XE Wireless Controller Software for Cisco...
High
Unreviewed
CVE-2021-34767
was published
May 24, 2022
On F5 BIG-IP Advanced WAF, ASM, and APM 16.1.x versions prior to 16.1.2.1, 15.1.x versions prior...
High
Unreviewed
CVE-2022-26890
was published
May 6, 2022
In WAVM through 2018-07-26, a crafted file sent to the WebAssembly Virtual Machine may cause a...
High
Unreviewed
CVE-2018-16766
was published
May 13, 2022
Cloud Native Computing Foundation (CNCF) CNI (Container Networking Interface) 0.7.4 has a network...
High
Unreviewed
CVE-2019-9946
was published
May 13, 2022
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local...
High
Unreviewed
CVE-2017-0604
was published
May 13, 2022
In addOrReplacePhoneAccount of PhoneAccountRegistrar.java, there is a possible way to enable a...
High
Unreviewed
CVE-2023-20915
was published
Jan 26, 2023
In onPackageRemoved of AccessibilityManagerService.java, there is a possibility to automatically...
High
Unreviewed
CVE-2023-20921
was published
Jan 26, 2023
Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before...
High
Unreviewed
CVE-2022-36278
was published
Feb 16, 2023
Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools...
High
Unreviewed
CVE-2022-27808
was published
Feb 16, 2023
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will...
High
Unreviewed
CVE-2023-1668
was published
Apr 11, 2023
An issue was discovered in ONOS 2.5.1. IntentManager attempts to install the IPv6 flow rules of...
High
Unreviewed
CVE-2022-29605
was published
Apr 20, 2023
An issue was discovered in ONOS 2.5.1. Modification of an existing intent to have the same source...
High
Unreviewed
CVE-2022-29607
was published
Apr 20, 2023
there is a possible way to bypass due to a logic error in the code. This could lead to local...
High
Unreviewed
CVE-2024-32896
was published
Jun 13, 2024
Insufficient authentication flow in Checkmk before 2.2.0p17, 2.1.0p37 and 2.0.0p39 allows...
High
Unreviewed
CVE-2023-31211
was published
Jan 12, 2024
Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update...
High
Unreviewed
CVE-2023-41376
was published
Aug 29, 2023
A vulnerability in the DHCP Snooping feature of Cisco IOS XE Software on Software-Defined Access ...
High
Unreviewed
CVE-2024-20480
was published
Sep 25, 2024
In the Linux kernel, the following vulnerability has been resolved:
mm: call the...
High
Unreviewed
CVE-2024-47745
was published
Oct 21, 2024
ProTip!
Advisories are also available from the
GraphQL API