GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
15,579 advisories
Filter by severity
Multiple cross-site scripting (XSS) vulnerabilities in js/viewer.js in ownCloud before 4.5.12 and...
Low
Unreviewed
CVE-2013-2150
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.8 allow remote...
Low
Unreviewed
CVE-2013-1822
was published
May 17, 2022
Incomplete blacklist vulnerability in lib/migrate.php in ownCloud before 4.0.13 and 4.5.x before...
Low
Unreviewed
CVE-2013-1851
was published
May 17, 2022
The RAND_bytes function in libssh before 0.6.3, when forking is enabled, does not properly reset...
Low
Unreviewed
CVE-2014-0017
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in the iThoughtsHD app 4.19 for iOS on iPad devices,...
Low
Unreviewed
CVE-2014-1826
was published
May 17, 2022
The setup script in Domain Technologie Control (DTC) before 0.34.1 uses world-readable...
Low
Unreviewed
CVE-2011-3196
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in Domain Technologie Control (DTC) before 0...
Low
Unreviewed
CVE-2011-3199
was published
May 17, 2022
Luci in Red Hat Conga stores the user's username and password in a Base64 encoded string in the...
Low
Unreviewed
CVE-2012-3359
was published
May 17, 2022
Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow...
Low
Unreviewed
CVE-2013-7347
was published
May 17, 2022
Mozilla Firefox before 28.0.1 on Android processes a file: URL by copying a local file onto the...
Low
Unreviewed
CVE-2014-1515
was published
May 17, 2022
Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource"...
Low
Unreviewed
CVE-2011-4573
was published
May 17, 2022
The Settings module in Websense Triton Unified Security Center 7.7.3 before Hotfix 31, Web Filter...
Low
Unreviewed
CVE-2014-0347
was published
May 17, 2022
The Artiva Agency Single Sign-On (SSO) implementation in Artiva Workstation 1.3.x before 1.3.9,...
Low
Unreviewed
CVE-2014-0348
was published
May 17, 2022
Citrix VDI-in-a-Box 5.3.x before 5.3.6 and 5.4.x before 5.4.3 allows local users to obtain...
Low
Unreviewed
CVE-2014-2690
was published
May 17, 2022
Unspecified vulnerability in the Oracle OpenSSO component in Oracle Fusion Middleware 8.0 Update...
Low
Unreviewed
CVE-2014-0465
was published
May 17, 2022
Unspecified vulnerability in Oracle MySQL Server 5.6.15 and earlier allows remote authenticated...
Low
Unreviewed
CVE-2014-2451
was published
May 17, 2022
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain...
Low
Unreviewed
CVE-2014-2464
was published
May 17, 2022
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain...
Low
Unreviewed
CVE-2014-2466
was published
May 17, 2022
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain...
Low
Unreviewed
CVE-2014-2445
was published
May 17, 2022
Unspecified vulnerability in the Oracle Agile PLM Framework component in Oracle Supply Chain...
Low
Unreviewed
CVE-2014-2467
was published
May 17, 2022
Unspecified vulnerability in the Oracle Transportation Management component in Oracle Supply...
Low
Unreviewed
CVE-2014-2459
was published
May 17, 2022
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages...
Low
Unreviewed
CVE-2013-1764
was published
May 17, 2022
The Ubuntu AccountsService package before 0.6.14-1git1ubuntu1.1 does not properly drop privileges...
Low
Unreviewed
CVE-2011-4406
was published
May 17, 2022
Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when...
Low
Unreviewed
CVE-2013-1917
was published
May 17, 2022
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1...
Low
Unreviewed
CVE-2014-2287
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API