GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,950
Erlang
39
GitHub Actions
38
Go
2,603
Maven
5,000+
npm
4,250
NuGet
755
pip
4,013
Pub
12
RubyGems
953
Rust
1,048
Swift
45
Unreviewed advisories
All unreviewed
5,000+
253 advisories
Filter by severity
Exposure of Sensitive Information in Hadoop
Critical
CVE-2017-15718
was published
for
org.apache.hadoop:hadoop-main
(Maven)
Dec 21, 2018
Insecure Permissions in Gogs
Critical
CVE-2019-14544
was published
for
gogs.io/gogs
(Go)
May 18, 2021
Argo CD will blindly trust JWT claims if anonymous access is enabled
Critical
CVE-2022-29165
was published
for
github.com/argoproj/argo-cd
(Go)
May 24, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Hadoop
Critical
CVE-2016-3086
was published
for
org.apache.hadoop:hadoop-yarn-server-nodemanager
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
Critical
CVE-2017-1000362
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
An exploitable arbitrary memory read vulnerability exists in the KCodes NetUSB.ko kernel module...
Critical
Unreviewed
CVE-2019-5016
was published
May 24, 2022
Cisco Small Business 220 devices with firmware before 1.0.1.1 have a hardcoded SNMP community,...
Critical
Unreviewed
CVE-2016-1473
was published
May 17, 2022
Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) in EMC Avamar Server before 7.3.0-233...
Critical
Unreviewed
CVE-2016-0903
was published
May 17, 2022
Weave GitOps leaked cluster credentials into logs on connection errors
Critical
CVE-2022-31098
was published
for
github.com/weaveworks/weave-gitops
(Go)
Jun 23, 2022
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request...
Critical
Unreviewed
CVE-2017-11502
was published
May 17, 2022
An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root...
Critical
Unreviewed
CVE-2017-7317
was published
May 17, 2022
A vulnerability in the symbolic link (symlink) creation functionality of the AutoVNF tool for the...
Critical
Unreviewed
CVE-2017-6708
was published
May 17, 2022
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and...
Critical
Unreviewed
CVE-2015-5729
was published
May 17, 2022
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and...
Critical
Unreviewed
CVE-2016-1557
was published
May 17, 2022
Schneider Electric Modicon TM221CE16R 1.3.3.3 devices allow remote attackers to discover the...
Critical
Unreviewed
CVE-2017-7575
was published
May 17, 2022
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to...
Critical
Unreviewed
CVE-2016-10105
was published
May 17, 2022
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. An...
Critical
Unreviewed
CVE-2017-5166
was published
May 17, 2022
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to...
Critical
Unreviewed
CVE-2017-6070
was published
May 17, 2022
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x...
Critical
Unreviewed
CVE-2016-9885
was published
May 17, 2022
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2...
Critical
Unreviewed
CVE-2016-5757
was published
May 17, 2022
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect...
Critical
Unreviewed
CVE-2019-18823
was published
May 24, 2022
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006...
Critical
Unreviewed
CVE-2016-1112
was published
May 17, 2022
eWON devices with firmware before 10.1s0 omit RBAC for I/O server information and status requests...
Critical
Unreviewed
CVE-2015-7926
was published
May 17, 2022
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain...
Critical
Unreviewed
CVE-2016-2298
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API