GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
113 advisories
Filter by severity
There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription...
Moderate
Unreviewed
CVE-2022-0852
was published
Aug 29, 2022
Exposure of password hashes in notrinos/notrinos-erp
High
CVE-2022-2921
was published
for
notrinos/notrinos-erp
(Composer)
Aug 22, 2022
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier)...
Moderate
Unreviewed
CVE-2021-28559
was published
May 24, 2022
curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information...
Moderate
Unreviewed
CVE-2021-22876
was published
May 24, 2022
Mattermost Server: initial_load API exposes unnecessary information
High
CVE-2016-11066
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
Withdrawn Advisory: Incorrect Authorization in cross-fetch
Moderate
CVE-2022-1365
was published
for
cross-fetch
(npm)
Apr 17, 2022
•
withdrawn
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository gnuboard...
High
Unreviewed
CVE-2022-1252
was published
Apr 12, 2022
Unauthenticated user can list hidden document from multiple velocity templates in XWiki
Moderate
CVE-2022-24820
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Apr 8, 2022
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
Moderate
CVE-2022-24819
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 8, 2022
Exposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointments
Critical
CVE-2022-0482
was published
for
alextselegidis/easyappointments
(Composer)
Mar 10, 2022
Forwarding of confidentials headers to third parties in fluture-node
Low
CVE-2022-24719
was published
for
fluture-node
(npm)
Mar 1, 2022
Exposure of sensitive information in follow-redirects
High
CVE-2022-0155
was published
for
follow-redirects
(npm)
Jan 12, 2022
ProTip!
Advisories are also available from the
GraphQL API