GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
562 advisories
Filter by severity
In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory...
Moderate
Unreviewed
CVE-2021-39648
was published
Dec 16, 2021
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from...
Moderate
Unreviewed
CVE-2021-39915
was published
Dec 14, 2021
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1, and 11.5 is vulnerable to...
Moderate
Unreviewed
CVE-2021-38931
was published
Dec 10, 2021
Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will...
Moderate
Unreviewed
CVE-2021-38505
was published
Dec 9, 2021
Under certain circumstances, asynchronous functions could have caused a navigation to fail but...
Moderate
Unreviewed
CVE-2021-43536
was published
Dec 9, 2021
An information disclosure vulnerability in the ArcGIS Service Directory in Esri ArcGIS Enterprise...
Moderate
Unreviewed
CVE-2021-29115
was published
Dec 8, 2021
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file...
Moderate
Unreviewed
CVE-2021-43039
was published
Dec 7, 2021
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could...
Moderate
Unreviewed
CVE-2021-43043
was published
Dec 7, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow a low level user to reas of the application...
Moderate
Unreviewed
CVE-2021-29716
was published
Dec 4, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated to view or edit a Jupyter...
Moderate
Unreviewed
CVE-2021-29867
was published
Dec 4, 2021
IBM Cognos Analytics 11.1.7 and 11.2.0 could be vulnerable to client side vulnerabilties due to a...
Moderate
Unreviewed
CVE-2021-29719
was published
Dec 4, 2021
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s...
Moderate
Unreviewed
CVE-2021-42116
was published
Dec 1, 2021
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message...
Moderate
Unreviewed
CVE-2021-44225
was published
Nov 27, 2021
Azure Active Directory Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2021-42306
was published
Nov 25, 2021
Insufficient policy enforcement in Autofill in Google Chrome prior to 95.0.4638.69 allowed a...
Moderate
Unreviewed
CVE-2021-38004
was published
Nov 24, 2021
Apache Ozone exposes OM, SCM and Datanode metadata
Moderate
CVE-2021-41532
was published
for
org.apache.ozone:ozone-main
(Maven)
Nov 23, 2021
Philips MRI 1.5T and MRI 3T Version 5.x.x exposes sensitive information to an actor not...
Moderate
Unreviewed
CVE-2021-42744
was published
Nov 20, 2021
PSP protection against improperly configured side channels may lead to potential information...
Moderate
Unreviewed
CVE-2021-26312
was published
Nov 17, 2021
Insufficient validation of guest context in the SNP Firmware could lead to a potential loss of...
Moderate
Unreviewed
CVE-2021-26327
was published
Nov 17, 2021
Electron's sandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage API
Moderate
CVE-2021-39184
was published
for
electron
(npm)
Oct 12, 2021
Druid ingestion system Authenticated users can read data from other sources than intended
Moderate
CVE-2021-36749
was published
for
org.apache.druid:druid-core
(Maven)
Sep 27, 2021
CSRF token exposure in TYPO3 extension
Moderate
CVE-2021-36793
was published
for
lms/routes
(Composer)
Sep 2, 2021
Exposed phpinfo() leadked via documentation files
Moderate
CVE-2021-37704
was published
for
phpfastcache/phpfastcache
(Composer)
Aug 30, 2021
Archive package allows chmod of file outside of unpack target directory
Moderate
CVE-2021-32760
was published
for
github.com/containerd/containerd
(Go)
Jul 26, 2021
The reset password form reveal users email address
Moderate
CVE-2021-32731
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Jul 2, 2021
ProTip!
Advisories are also available from the
GraphQL API