GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,286
Erlang
31
GitHub Actions
21
Go
2,058
Maven
5,000+
npm
3,742
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
515 advisories
Filter by severity
Symfony Http-Kernel has non-constant time comparison in UriSigner
High
CVE-2019-18887
was published
for
symfony/http-kernel
(Composer)
Mar 26, 2022
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised...
High
Unreviewed
CVE-2020-36517
was published
Mar 11, 2022
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a...
Moderate
Unreviewed
CVE-2021-44421
was published
Mar 11, 2022
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
High
Unreviewed
CVE-2021-42016
was published
Mar 9, 2022
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate...
Moderate
Unreviewed
CVE-2022-0564
was published
Feb 22, 2022
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable...
Critical
Unreviewed
CVE-2022-23303
was published
Feb 15, 2022
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are...
Critical
Unreviewed
CVE-2022-23304
was published
Feb 15, 2022
Exposure of Sensitive Information in snipe/snipe-it
Moderate
CVE-2022-0569
was published
for
snipe/snipe-it
(Composer)
Feb 15, 2022
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure...
Moderate
Unreviewed
CVE-2021-0524
was published
Feb 12, 2022
The password-reset form in ServiceNow Orlando provides different responses to invalid...
Moderate
Unreviewed
CVE-2021-45901
was published
Feb 11, 2022
Apache Hive Information Exposure and Observable Timing Discrepancy
Moderate
CVE-2020-1926
was published
for
org.apache.hive:hive
(Maven)
Feb 9, 2022
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under...
Moderate
Unreviewed
CVE-2021-39021
was published
Feb 3, 2022
Observable Response Discrepancy in Flask-AppBuilder
Moderate
CVE-2022-21659
was published
for
Flask-AppBuilder
(pip)
Feb 1, 2022
In Bromite through 78.0.3904.130, there are adblock rules in the release APK; therefore, probing...
Moderate
Unreviewed
CVE-2019-25056
was published
Jan 27, 2022
Observable Discrepancy and Observable Timing Discrepancy in Jenkins Configuration as Code Plugin
Low
CVE-2022-23106
was published
for
io.jenkins:configuration-as-code
(Maven)
Jan 21, 2022
In NocoDB, versions 0.9 to 0.83.8 are vulnerable to Observable Discrepancy in the password-reset...
Moderate
Unreviewed
CVE-2022-22120
was published
Jan 11, 2022
ManageEngine ADSelfService Plus below build 6116 contains an observable response discrepancy in...
Moderate
Unreviewed
CVE-2021-20147
was published
Jan 4, 2022
A vulnerability in SonicWall SMA100 password change API allows a remote unauthenticated attacker...
High
Unreviewed
CVE-2021-20049
was published
Dec 24, 2021
An issue was discovered in UTI Mutual fund Android application 5.4.18 and prior, allows attackers...
Moderate
Unreviewed
CVE-2020-35398
was published
Dec 24, 2021
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam...
Moderate
Unreviewed
CVE-2021-44875
was published
Dec 22, 2021
Dalmark Systems Systeam 2.22.8 build 1724 is vulnerable to User enumeration. The Systeam...
Moderate
Unreviewed
CVE-2021-44876
was published
Dec 22, 2021
Thinfinity VirtualUI before 3.0 allows a malicious actor to enumerate users registered in the OS ...
Moderate
Unreviewed
CVE-2021-44554
was published
Dec 21, 2021
In getNeighboringCellInfo of PhoneInterfaceManager.java, there is a possible way to determine...
Low
Unreviewed
CVE-2021-0987
was published
Dec 16, 2021
In hasManageOngoingCallsPermission of TelecomServiceImpl.java, there is a possible way to...
Low
Unreviewed
CVE-2021-0989
was published
Dec 16, 2021
In getLaunchedFromUid and getLaunchedFromPackage of ActivityClientController.java, there is a...
Low
Unreviewed
CVE-2021-0988
was published
Dec 16, 2021
ProTip!
Advisories are also available from the
GraphQL API