GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
117,957 advisories
Filter by severity
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4...
Moderate
Unreviewed
CVE-2016-2045
was published
May 17, 2022
The IBM WebSphere DataPower XC10 appliance 2.1 before 2.1.0.3 allows remote attackers to hijack...
Moderate
Unreviewed
CVE-2015-1893
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Meeting...
Moderate
Unreviewed
CVE-2016-1451
was published
May 17, 2022
The Multicast DNS (mDNS) responder in Synology DiskStation Manager (DSM) before 3.1 inadvertently...
Moderate
Unreviewed
CVE-2015-2809
was published
May 17, 2022
WebSheet in Apple iOS before 9.2.1 allows remote attackers to read or write to cookies by...
Moderate
Unreviewed
CVE-2016-1730
was published
May 17, 2022
Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote...
Moderate
Unreviewed
CVE-2016-1334
was published
May 17, 2022
Cisco TelePresence Video Communication Server (VCS) X8.1 through X8.7, as used in conjunction...
Moderate
Unreviewed
CVE-2016-1316
was published
May 17, 2022
The tipc_nl_compat_link_dump function in net/tipc/netlink_compat.c in the Linux kernel through 4...
Moderate
Unreviewed
CVE-2016-5243
was published
May 17, 2022
Cisco Unified Communications Manager 11.5(0.98000.480) allows remote authenticated users to...
Moderate
Unreviewed
CVE-2016-1317
was published
May 17, 2022
Unspecified vulnerability in the Sun ZFS Storage Appliance Kit (AK) component in Oracle Sun...
Moderate
Unreviewed
CVE-2016-5486
was published
May 17, 2022
DokuWiki 2014-05-05a and earlier, when using Active Directory for LDAP authentication, allows...
Moderate
Unreviewed
CVE-2014-8764
was published
May 17, 2022
The MediaTek Wi-Fi driver in Android before 2016-07-05 on Android One devices allows attackers to...
Moderate
Unreviewed
CVE-2016-3810
was published
May 17, 2022
Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated...
Moderate
Unreviewed
CVE-2016-5092
was published
May 17, 2022
An elevation of privilege vulnerability in the Account Manager Service in Android 7.0 before 2016...
Moderate
Unreviewed
CVE-2016-6718
was published
May 17, 2022
media/libmediaplayerservice/MetadataRetrieverClient.cpp in mediaserver in Android 4.x before 4.4...
Moderate
Unreviewed
CVE-2016-3764
was published
May 17, 2022
The kernel in Android before 2016-10-05 on Nexus 5, Nexus 5X, Nexus 6, Nexus 6P, Nexus 9, Nexus...
Moderate
Unreviewed
CVE-2016-6684
was published
May 17, 2022
The NVIDIA profiler in Android before 2016-10-05 on Nexus 9 devices allows attackers to obtain...
Moderate
Unreviewed
CVE-2016-6687
was published
May 17, 2022
The p2m_teardown function in arch/arm/p2m.c in Xen 4.4.x through 4.6.x allows local guest OS...
Moderate
Unreviewed
CVE-2016-5242
was published
May 17, 2022
SQL injection vulnerability in Cisco Unified Communications Manager 10.5(2.13900.9) allows remote...
Moderate
Unreviewed
CVE-2016-1308
was published
May 17, 2022
Panasonic FPWIN Pro 5.x through 7.x before 7.130 accesses an uninitialized pointer, which allows...
Moderate
Unreviewed
CVE-2016-4498
was published
May 17, 2022
Cross-site scripting (XSS) vulnerability in Cisco Unity Connection 11.5(0.199) allows remote...
Moderate
Unreviewed
CVE-2016-1310
was published
May 17, 2022
The DSA algorithm implementation in SAP SAPCRYPTOLIB 5.555.38 does not properly check signatures,...
Moderate
Unreviewed
CVE-2016-4407
was published
May 17, 2022
Heap-based buffer overflow in Panasonic FPWIN Pro 5.x through 7.x before 7.130 allows local users...
Moderate
Unreviewed
CVE-2016-4499
was published
May 17, 2022
nasm v2.16 was discovered to contain a stack overflow in the Ndisasm component
Moderate
Unreviewed
CVE-2022-41420
was published
Oct 4, 2022
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The...
Moderate
Unreviewed
CVE-2022-42300
was published
Oct 4, 2022
ProTip!
Advisories are also available from the
GraphQL API