GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,087
Maven
5,000+
npm
3,751
NuGet
674
pip
3,437
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
7,534 advisories
Filter by severity
Directory Traversal in fbr-client
High
CVE-2017-16217
was published
for
fbr-client
(npm)
Jul 23, 2018
Directory Traversal in dgard8.lab6
High
CVE-2017-16218
was published
for
dgard8.lab6
(npm)
Jul 23, 2018
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
High
CVE-2011-1950
was published
for
Plone
(pip)
Jul 23, 2018
Plone allows remote attackers to read hidden folder contents
High
CVE-2012-5503
was published
for
Plone
(pip)
Jul 23, 2018
Plone and Zope2 vulnerable to unauthorized access to restricted attributes
High
CVE-2012-5489
was published
for
Plone
(pip)
Jul 23, 2018
High severity vulnerability that affects Plone and Zope2
High
CVE-2011-2528
was published
for
Plone
(pip)
Jul 23, 2018
HTTP header injection in Plone and Zope2
High
CVE-2012-5486
was published
for
Plone
(pip)
Jul 23, 2018
Improper query string handling in Django
High
CVE-2010-4534
was published
for
Django
(pip)
Jul 23, 2018
Django Cross-Site Request Forgery vulnerability
High
CVE-2011-4140
was published
for
Django
(pip)
Jul 23, 2018
Plone and Zope2 do not reseed pseudo-random number generator
High
CVE-2012-6661
was published
for
Plone
(pip)
Jul 23, 2018
Plone and Zope2 affected by Race Condition
High
CVE-2012-5507
was published
for
Plone
(pip)
Jul 23, 2018
feedparser denial of service vulnerability
High
CVE-2011-1156
was published
for
feedparser
(pip)
Jul 23, 2018
Kcapifony gem for Ruby places database user passwords on the command line
High
CVE-2014-5001
was published
for
kcapifony
(RubyGems)
Jul 23, 2018
mime Regular Expression Denial of Service when MIME lookup performed on untrusted user input
High
CVE-2017-16138
was published
for
mime
(npm)
Jul 20, 2018
Denial of Service vulnerability with large JSON payloads in fastify
High
CVE-2018-3711
was published
for
fastify
(npm)
Jul 18, 2018
Path Traversal in crud-file-server
High
CVE-2018-3733
was published
for
crud-file-server
(npm)
Jul 18, 2018
Withdrawn Advisory: mariadb was malware
High
CVE-2017-16046
was published
for
mariadb
(npm)
Jul 18, 2018
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API