GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,470
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
553 advisories
Filter by severity
In PackageInstaller, there is a possible way to determine whether an app is installed, without...
Low
Unreviewed
CVE-2022-20318
was published
Aug 13, 2022
In ActivityManager, there is a possible way to determine whether an app is installed, without...
Low
Unreviewed
CVE-2022-20320
was published
Aug 13, 2022
Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to...
Moderate
Unreviewed
CVE-2021-33149
was published
May 13, 2022
Ampere Altra devices before 1.08g and Ampere Altra Max devices before 2.05a allow attackers to...
High
Unreviewed
CVE-2022-37459
was published
Aug 18, 2022
While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was...
Moderate
Unreviewed
CVE-2022-26382
was published
Dec 22, 2022
An information leakage vulnerability in the Bluetooth Low Energy advertisement scan response in...
Moderate
Unreviewed
CVE-2020-35473
was published
Nov 8, 2022
All CODESYS Visualization versions before V4.2.0.0 generate a login dialog vulnerable to...
Moderate
Unreviewed
CVE-2022-1989
was published
Aug 24, 2022
NVIDIA BMC contains a vulnerability in IPMI handler, where an unauthorized attacker can use...
Moderate
Unreviewed
CVE-2022-42288
was published
Jan 13, 2023
An information-disclosure vulnerability exists on select NXP devices when configured in Serial...
Moderate
Unreviewed
CVE-2022-45163
was published
Nov 19, 2022
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU...
High
Unreviewed
CVE-2021-46778
was published
Aug 11, 2022
The Splunk Enterprise REST API allows enumeration of usernames via the lockout error message. The...
Moderate
Unreviewed
CVE-2021-33845
was published
May 7, 2022
A timing attack in SVG rendering in Google Chrome prior to 60.0.3112.78 for Linux, Windows, and...
Moderate
Unreviewed
CVE-2017-5107
was published
May 13, 2022
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to...
Moderate
Unreviewed
CVE-2019-1559
was published
May 13, 2022
User enumeration leak using switch user functionality in Symfony
Moderate
CVE-2019-18886
was published
for
symfony/security-http
(Composer)
Dec 2, 2019
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel...
Moderate
Unreviewed
CVE-2019-9495
was published
May 13, 2022
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2),...
High
Unreviewed
CVE-2017-6168
was published
May 13, 2022
Symantec IntelligenceCenter 3.3 is vulnerable to the Return of the Bleichenbacher Oracle Threat ...
Moderate
Unreviewed
CVE-2017-18268
was published
May 13, 2022
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks...
Moderate
Unreviewed
CVE-2019-9494
was published
May 13, 2022
Symantec SSL Visibility (SSLV) 3.8.4FC, 3.10 prior to 3.10.4.1, 3.11, and 3.12 prior to 3.12.2.1...
Moderate
Unreviewed
CVE-2017-15533
was published
May 13, 2022
A Bleichenbacher type side-channel based padding oracle attack was found in the way nettle...
Moderate
Unreviewed
CVE-2018-16869
was published
May 13, 2022
A Bleichenbacher type side-channel based padding oracle attack was found in the way gnutls...
Moderate
Unreviewed
CVE-2018-16868
was published
May 13, 2022
The RSA and DSA decryption code in Nettle makes it easier for attackers to discover private keys...
High
Unreviewed
CVE-2016-6489
was published
May 13, 2022
Observable Timing Discrepancy in OpenMage LTS
High
CVE-2020-15151
was published
for
openmage/magento-lts
(Composer)
Aug 19, 2020
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software...
Moderate
Unreviewed
CVE-2018-5407
was published
May 13, 2022
A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an...
Moderate
Unreviewed
CVE-2018-0134
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API