GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
1,996
Maven
5,000+
npm
3,709
NuGet
661
pip
3,348
Pub
11
RubyGems
885
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
235,055 advisories
Filter by severity
In writeToParcel of MediaPlayer.java, there is a possible serialization/deserialization mismatch...
High
Unreviewed
CVE-2018-9474
was published
Nov 20, 2024
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds read due to a missing...
Moderate
Unreviewed
CVE-2018-9485
was published
Nov 20, 2024
In bta_dm_remove_sec_dev_entry of bta_dm_act.cc, there is a possible out of bounds read due to a...
Moderate
Unreviewed
CVE-2018-9483
was published
Nov 20, 2024
In bta_hd_get_report_act of bta_hd_act.cc, there is a possible out-of-bounds read due to improper...
Moderate
Unreviewed
CVE-2018-9480
was published
Nov 20, 2024
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to...
Critical
Unreviewed
CVE-2018-9471
was published
Nov 20, 2024
In setVpnForcedLocked of Vpn.java, there is a possible blocking of internet traffic through vpn...
Moderate
Unreviewed
CVE-2018-9487
was published
Nov 20, 2024
In process_service_attr_req and process_service_search_attr_req of sdp_server.cc, there is an out...
Critical
Unreviewed
CVE-2018-9479
was published
Nov 20, 2024
In hidh_l2cif_data_ind of hidh_conn.cc, there is a possible out of bounds read due to a missing...
Moderate
Unreviewed
CVE-2018-9486
was published
Nov 20, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2024-52471
was published
Nov 20, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2024-52473
was published
Nov 20, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2024-52472
was published
Nov 20, 2024
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of...
Critical
Unreviewed
CVE-2024-10094
was published
Nov 20, 2024
Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2...
Unknown
Unreviewed
CVE-2024-51209
was published
Nov 20, 2024
The Clone plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and...
High
Unreviewed
CVE-2024-10913
was published
Nov 20, 2024
File Upload vulnerability in change-image.php in Anuj Kumar's Boat Booking System version 1.0...
Unknown
Unreviewed
CVE-2024-51208
was published
Nov 20, 2024
Buffer overflow vulnerability in OllyDbg, version 1.10, which could allow a local attacker to...
High
Unreviewed
CVE-2024-11495
was published
Nov 20, 2024
The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin...
Moderate
Unreviewed
CVE-2024-11154
was published
Nov 20, 2024
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege...
Critical
Unreviewed
CVE-2024-9479
was published
Nov 20, 2024
Improper Privilege Management vulnerability in upKeeper Solutions upKeeper Instant Privilege...
Critical
Unreviewed
CVE-2024-9478
was published
Nov 20, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
High
Unreviewed
CVE-2024-52470
was published
Nov 20, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Buying Buddy Buying Buddy IDX CRM allows...
High
Unreviewed
CVE-2024-52446
was published
Nov 20, 2024
Deserialization of Untrusted Data vulnerability in Modeltheme QRMenu Restaurant QR Menu Lite...
High
Unreviewed
CVE-2024-52445
was published
Nov 20, 2024
Deserialization of Untrusted Data vulnerability in Bueno Labs Pvt. Ltd. Xpresslane Fast Checkout...
Critical
Unreviewed
CVE-2024-52440
was published
Nov 20, 2024
Deserialization of Untrusted Data vulnerability in Mark O’Donnell Team Rosters allows Object...
Critical
Unreviewed
CVE-2024-52439
was published
Nov 20, 2024
Incorrect Privilege Assignment vulnerability in Userplus UserPlus allows Privilege Escalation...
Critical
Unreviewed
CVE-2024-52442
was published
Nov 20, 2024
ProTip!
Advisories are also available from the
GraphQL API