GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where...
High
Unreviewed
CVE-2019-3977
was published
May 24, 2022
An issue was discovered in WeeChat before 2.7.1 (0.4.0 to 2.7 are affected). A malformed message...
High
Unreviewed
CVE-2020-9759
was published
May 24, 2022
A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0...
High
Unreviewed
CVE-2023-22635
was published
Apr 11, 2023
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with...
High
Unreviewed
CVE-2023-37864
was published
Aug 9, 2023
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2023-39474
was published
May 3, 2024
A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780-0DA00) (All...
High
Unreviewed
CVE-2024-30206
was published
May 14, 2024
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the...
High
Unreviewed
CVE-2024-33118
was published
May 6, 2024
Cargo prior to Rust 1.26.0 may download the wrong dependency
High
CVE-2019-16760
was published
for
cargo
(Rust)
May 24, 2022
A download of code without integrity check vulnerability in PLCnext products allows an remote...
High
Unreviewed
CVE-2023-46144
was published
Dec 14, 2023
A download of code without integrity check vulnerability in the "execute restore src-vis" command...
High
Unreviewed
CVE-2021-44168
was published
Jan 5, 2022
In Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org...
High
Unreviewed
CVE-2024-30205
was published
Mar 25, 2024
Django vulnerable to Reflected File Download attack
High
CVE-2022-36359
was published
for
Django
(pip)
Aug 11, 2022
Gradio lacks integrity checking on the downloaded FRP client
High
CVE-2024-47867
was published
for
gradio
(pip)
Oct 10, 2024
ECOVACS robot lawnmowers and vacuums use a deterministic symmetric key to decrypt firmware...
High
Unreviewed
CVE-2024-52331
was published
Jan 23, 2025
ProTip!
Advisories are also available from the
GraphQL API