GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,124
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
284 advisories
Filter by severity
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a...
Moderate
Unreviewed
CVE-2023-5851
was published
Nov 1, 2023
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote...
Moderate
Unreviewed
CVE-2023-5853
was published
Nov 1, 2023
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed...
Moderate
Unreviewed
CVE-2023-5858
was published
Nov 1, 2023
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a...
Moderate
Unreviewed
CVE-2023-5859
was published
Nov 1, 2023
An unauthenticated attacker can send a ping request from one network to another through an error...
Moderate
Unreviewed
CVE-2024-24782
was published
Feb 13, 2024
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000,...
High
Unreviewed
CVE-2000-1218
was published
Apr 30, 2022
By default, DNS servers on Windows NT 4.0 and Windows 2000 Server cache glue records received...
Moderate
Unreviewed
CVE-2001-1452
was published
Apr 30, 2022
FreeScripts VisitorBook LE (visitorbook.pl) logs the reverse DNS name of a visiting host, which...
Moderate
Unreviewed
CVE-2003-0981
was published
Apr 29, 2022
MeshCentral cross-site websocket hijacking (CSWSH) vulnerability
High
CVE-2024-26135
was published
for
meshcentral
(npm)
Feb 21, 2024
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected...
Critical
Unreviewed
CVE-2014-125071
was published
Jan 9, 2023
An unauthenticated remote attacker can perform a remote code execution due to an origin...
Moderate
Unreviewed
CVE-2024-25996
was published
Mar 12, 2024
Cross-origin images can be read in violation of the same-origin policy by exporting an image...
Moderate
Unreviewed
CVE-2019-9797
was published
May 24, 2022
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content...
High
Unreviewed
CVE-2019-9803
was published
May 24, 2022
If WebRTC permission is requested from documents with data: or blob: URLs, the permission...
Moderate
Unreviewed
CVE-2019-9808
was published
May 24, 2022
Images from a different domain can be read using a canvas object in some circumstances. This...
Moderate
Unreviewed
CVE-2019-9817
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep...
High
Unreviewed
CVE-2019-16237
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep...
High
Unreviewed
CVE-2019-16235
was published
May 24, 2022
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection...
Moderate
Unreviewed
CVE-2019-16275
was published
May 24, 2022
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution...
High
Unreviewed
CVE-2019-19019
was published
May 24, 2022
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for...
Moderate
Unreviewed
CVE-2019-5062
was published
May 24, 2022
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension...
Moderate
Unreviewed
CVE-2019-1413
was published
May 24, 2022
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab...
Moderate
Unreviewed
CVE-2023-23601
was published
Jun 2, 2023
The underlying feedback mechanism of
Rockwell Automation's FactoryTalk System Services that...
Moderate
Unreviewed
CVE-2023-2639
was published
Jun 13, 2023
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site...
Critical
Unreviewed
CVE-2023-0957
was published
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API