GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
158,245 advisories
Filter by severity
SAP 3D Visual Enterprise Viewer (VEV) allows remote attackers to execute arbitrary code via a...
Moderate
Unreviewed
CVE-2015-8029
was published
May 17, 2022
Techno Project Japan Enisys Gw before 1.4.1 allows remote authenticated users to write to...
Moderate
Unreviewed
CVE-2015-5669
was published
May 17, 2022
The Breezy application for Android does not verify that the server hostname matches a domain name...
Moderate
Unreviewed
CVE-2012-5811
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers...
Moderate
Unreviewed
CVE-2014-4871
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tpl and (2)...
Moderate
Unreviewed
CVE-2014-4743
was published
May 17, 2022
Directory traversal vulnerability in report/reportViewAction.jsp in Progress Software OpenEdge 11...
Moderate
Unreviewed
CVE-2014-8555
was published
May 17, 2022
Cisco AnyConnect Secure Mobility Client 4.0(.00051) and earlier does not properly implement...
Moderate
Unreviewed
CVE-2015-0663
was published
May 17, 2022
Multiple cross-site scripting (XSS) vulnerabilities in the help pages in Cisco Common Services,...
Moderate
Unreviewed
CVE-2015-0594
was published
May 17, 2022
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 does not throttle file...
Moderate
Unreviewed
CVE-2015-8003
was published
May 17, 2022
The recycle bin feature in the Monster Menus module 7.x-1.21 before 7.x-1.24 for Drupal does not...
Moderate
Unreviewed
CVE-2015-8095
was published
May 17, 2022
Xen, possibly before 4.0.2, allows local 64-bit PV guests to cause a denial of service (host...
Moderate
Unreviewed
CVE-2011-1166
was published
May 17, 2022
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which...
Moderate
Unreviewed
CVE-2015-5643
was published
May 17, 2022
The default configuration of Cisco Small Business IP phones SPA 300 7.5.5 and SPA 500 7.5.5 does...
Moderate
Unreviewed
CVE-2015-0670
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in 4images 1.7.11 and earlier allows remote attackers to...
Moderate
Unreviewed
CVE-2015-7708
was published
May 17, 2022
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1...
Moderate
Unreviewed
CVE-2015-0987
was published
May 17, 2022
The Autonomic Networking Infrastructure (ANI) implementation in Cisco IOS allows remote attackers...
Moderate
Unreviewed
CVE-2015-0659
was published
May 17, 2022
AppleMNT.sys in Apple Boot Camp 5 before 5.1 allows local users to cause a denial of service ...
Moderate
Unreviewed
CVE-2014-1253
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in IBM Multi-Enterprise Integration Gateway 1.x through...
Moderate
Unreviewed
CVE-2015-4973
was published
May 17, 2022
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.1.0.7, 11.2.0.3,...
Moderate
Unreviewed
CVE-2014-6537
was published
May 17, 2022
Unspecified vulnerability in Oracle Sun Solaris 11 allows remote attackers to affect...
Moderate
Unreviewed
CVE-2014-4283
was published
May 17, 2022
Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute...
Moderate
Unreviewed
CVE-2015-0682
was published
May 17, 2022
LG Electronics Mobile WiFi router L-09C, L-03E, and L-04D does not restrict access to the web...
Moderate
Unreviewed
CVE-2014-7243
was published
May 17, 2022
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10...
Moderate
Unreviewed
CVE-2014-6534
was published
May 17, 2022
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect availability via...
Moderate
Unreviewed
CVE-2014-6497
was published
May 17, 2022
Directory traversal vulnerability in the unpacking functionality in dpkg before 1.15.9, 1.16.x...
Moderate
Unreviewed
CVE-2014-0471
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API