GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
24,509 advisories
Filter by severity
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages...
Critical
Unreviewed
CVE-2017-5391
was published
May 13, 2022
VMware vCenter Server (6.5 prior to 6.5 U1) contains an information disclosure vulnerability....
Critical
Unreviewed
CVE-2017-4923
was published
May 13, 2022
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands ...
Critical
Unreviewed
CVE-2017-5626
was published
May 13, 2022
A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to...
Critical
Unreviewed
CVE-2017-5719
was published
May 13, 2022
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3...
Critical
Unreviewed
CVE-2017-5821
was published
May 13, 2022
Revive Adserver before 4.0.1 allows remote attackers to execute arbitrary code via serialized...
Critical
Unreviewed
CVE-2017-5830
was published
May 13, 2022
A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and...
Critical
Unreviewed
CVE-2017-5802
was published
May 13, 2022
A vulnerability where WebExtensions can download and attempt to open a file of some non...
Critical
Unreviewed
CVE-2017-7821
was published
May 13, 2022
An issue with incorrect ownership model of "privateBrowsing" information exposed through...
Critical
Unreviewed
CVE-2017-5468
was published
May 13, 2022
A mechanism to bypass file system access protections in the sandbox using the file system request...
Critical
Unreviewed
CVE-2017-5456
was published
May 13, 2022
PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer...
Critical
Unreviewed
CVE-2017-5677
was published
May 13, 2022
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3...
Critical
Unreviewed
CVE-2017-5820
was published
May 13, 2022
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due...
Critical
Unreviewed
CVE-2017-8129
was published
May 13, 2022
An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100...
Critical
Unreviewed
CVE-2017-7899
was published
May 13, 2022
In ABB IP GATEWAY 3.39 and prior, some configuration files contain passwords stored in plain-text...
Critical
Unreviewed
CVE-2017-7933
was published
May 13, 2022
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible...
Critical
Unreviewed
CVE-2017-6182
was published
May 13, 2022
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due...
Critical
Unreviewed
CVE-2017-8119
was published
May 13, 2022
HPE LoadRunner before 12.53 Patch 4 and HPE Performance Center before 12.53 Patch 4 allow remote...
Critical
Unreviewed
CVE-2017-5789
was published
May 13, 2022
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3...
Critical
Unreviewed
CVE-2017-5823
was published
May 13, 2022
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1,...
Critical
Unreviewed
CVE-2017-6080
was published
May 13, 2022
An elevation of Privilege vulnerability exists in the Thermal Driver, where a missing bounds...
Critical
Unreviewed
CVE-2017-6274
was published
May 13, 2022
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to...
Critical
Unreviewed
CVE-2017-5600
was published
May 13, 2022
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1....
Critical
Unreviewed
CVE-2017-5619
was published
May 13, 2022
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a...
Critical
Unreviewed
CVE-2017-6326
was published
May 13, 2022
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1...
Critical
Unreviewed
CVE-2017-5738
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API