GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
10,867 advisories
Filter by severity
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally...
High
Unreviewed
CVE-2024-47238
was published
Dec 12, 2024
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-54107
was published
Dec 12, 2024
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-54109
was published
Dec 12, 2024
Read/Write vulnerability in the image decoding module
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-54108
was published
Dec 12, 2024
Vulnerability of improper access control in the secure input module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-54100
was published
Dec 12, 2024
Denial of service (DoS) vulnerability in the installation module
Impact: Successful exploitation...
Moderate
Unreviewed
CVE-2024-54101
was published
Dec 12, 2024
Duplicate Advisory: cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
Moderate
CVE-2024-12401
was published
for
github.com/cert-manager/cert-manager
(Go)
Dec 12, 2024
•
withdrawn
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-49073
was published
Dec 12, 2024
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
High
Unreviewed
CVE-2024-49057
was published
Dec 12, 2024
Windows Mobile Broadband Driver Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49087
was published
Dec 12, 2024
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and...
Critical
Unreviewed
CVE-2024-11737
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-52831
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-43755
was published
Dec 11, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation...
High
Unreviewed
CVE-2024-52982
was published
Dec 10, 2024
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM...
High
Unreviewed
CVE-2024-52051
was published
Dec 10, 2024
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input...
Moderate
Unreviewed
CVE-2024-45761
was published
Dec 9, 2024
Insufficient validation of filenames against control characters in Apache Subversion repositories...
Low
Unreviewed
CVE-2024-46901
was published
Dec 9, 2024
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified...
Moderate
Unreviewed
CVE-2024-12355
was published
Dec 9, 2024
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone...
Moderate
Unreviewed
CVE-2024-12353
was published
Dec 9, 2024
sigstore-java has a vulnerability with bundle verification
Low
CVE-2024-54140
was published
for
dev.sigstore:sigstore-java
(Maven)
Dec 5, 2024
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability...
Moderate
Unreviewed
CVE-2024-12138
was published
Dec 4, 2024
Improper Input Validation vulnerability in RestApp Inc. Online Ordering System allows Integer...
Moderate
Unreviewed
CVE-2024-7488
was published
Dec 4, 2024
An improper input validation vulnerability leads to device crashes in certain ASUS router models....
Moderate
Unreviewed
CVE-2024-11985
was published
Dec 4, 2024
Synapse allows a a malformed invite to break the invitee's `/sync`
High
CVE-2024-52815
was published
for
matrix-synapse
(pip)
Dec 3, 2024
ProTip!
Advisories are also available from the
GraphQL API