GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,344
Erlang
31
GitHub Actions
22
Go
2,109
Maven
5,000+
npm
3,765
NuGet
680
pip
3,453
Pub
12
RubyGems
892
Rust
887
Swift
37
Unreviewed advisories
All unreviewed
5,000+
10,801 advisories
Filter by severity
Duplicate Advisory: cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
Moderate
CVE-2024-12401
was published
for
github.com/cert-manager/cert-manager
(Go)
Dec 12, 2024
•
withdrawn
Microsoft Defender for Endpoint on Android Spoofing Vulnerability
High
Unreviewed
CVE-2024-49057
was published
Dec 12, 2024
Windows Mobile Broadband Driver Elevation of Privilege Vulnerability
Moderate
Unreviewed
CVE-2024-49073
was published
Dec 12, 2024
Windows Mobile Broadband Driver Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49087
was published
Dec 12, 2024
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
CWE-20: Improper Input Validation vulnerability exists that could lead to a denial of service and...
Critical
Unreviewed
CVE-2024-11737
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-52831
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-43755
was published
Dec 11, 2024
Animate versions 23.0.8, 24.0.5 and earlier are affected by an Improper Input Validation...
High
Unreviewed
CVE-2024-52982
was published
Dec 10, 2024
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM...
High
Unreviewed
CVE-2024-52051
was published
Dec 10, 2024
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input...
Moderate
Unreviewed
CVE-2024-45761
was published
Dec 9, 2024
Insufficient validation of filenames against control characters in Apache Subversion repositories...
Low
Unreviewed
CVE-2024-46901
was published
Dec 9, 2024
A vulnerability, which was classified as problematic, has been found in SourceCodester Phone...
Moderate
Unreviewed
CVE-2024-12353
was published
Dec 9, 2024
A vulnerability has been found in SourceCodester Phone Contact Manager System 1.0 and classified...
Moderate
Unreviewed
CVE-2024-12355
was published
Dec 9, 2024
sigstore-java has a vulnerability with bundle verification
Low
CVE-2024-54140
was published
for
dev.sigstore:sigstore-java
(Maven)
Dec 5, 2024
Improper Input Validation vulnerability in RestApp Inc. Online Ordering System allows Integer...
Moderate
Unreviewed
CVE-2024-7488
was published
Dec 4, 2024
A vulnerability classified as critical was found in horilla up to 1.2.1. This vulnerability...
Moderate
Unreviewed
CVE-2024-12138
was published
Dec 4, 2024
An improper input validation vulnerability leads to device crashes in certain ASUS router models....
Moderate
Unreviewed
CVE-2024-11985
was published
Dec 4, 2024
Synapse allows a a malformed invite to break the invitee's `/sync`
High
CVE-2024-52815
was published
for
matrix-synapse
(pip)
Dec 3, 2024
Memory corruption while processing API calls to NPU with invalid input.
High
Unreviewed
CVE-2024-43052
was published
Dec 2, 2024
A log spoofing flaw was found in the Tuned package due to improper sanitization of some API...
Moderate
Unreviewed
CVE-2024-52337
was published
Nov 26, 2024
When a URL is added to the map element, it is recorded in the database with sequential IDs. Upon...
Low
Unreviewed
CVE-2024-22117
was published
Nov 26, 2024
Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW
High
Unreviewed
CVE-2017-15832
was published
Nov 26, 2024
A vulnerability was found in welliamcao OpsManage 3.0.1/3.0.2/3.0.3/3.0.4/3.0.5. It has been...
Moderate
Unreviewed
CVE-2024-11662
was published
Nov 25, 2024
Logsign Unified SecOps Platform delete_gsuite_key_file Input Validation Arbitrary File Deletion...
Moderate
Unreviewed
CVE-2024-9257
was published
Nov 22, 2024
ProTip!
Advisories are also available from the
GraphQL API