GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
971 advisories
Filter by severity
Exposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an...
High
Unreviewed
CVE-2024-21813
was published
May 16, 2024
wolfictl leaks GitHub tokens to remote non-GitHub git servers
Moderate
CVE-2024-35183
was published
for
github.com/wolfi-dev/wolfictl
(Go)
May 15, 2024
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution...
Moderate
Unreviewed
CVE-2023-39478
was published
May 3, 2024
Vladimir Kononovich, a Security Researcher has found a flaw that using a inappropriate...
High
Unreviewed
CVE-2023-6096
was published
Apr 26, 2024
IPv6 enabled on IPv4-only network interfaces
Moderate
CVE-2024-32473
was published
for
github.com/docker/docker
(Go)
Apr 18, 2024
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of...
Moderate
Unreviewed
CVE-2024-21605
was published
Apr 12, 2024
DIRAC: Unauthorized users can read proxy contents during generation
High
CVE-2024-29905
was published
for
DIRAC
(pip)
Apr 9, 2024
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to...
High
Unreviewed
CVE-2024-3019
was published
Mar 28, 2024
Apache Airflow: DAG Code and Import Error Permissions Ignored
Moderate
CVE-2024-27906
was published
for
apache-airflow
(pip)
Feb 29, 2024
In the Linux kernel, the following vulnerability has been resolved:
mm/damon/dbgfs: fix 'struct...
Moderate
Unreviewed
CVE-2021-46937
was published
Feb 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
binder: fix async_free_space...
Moderate
Unreviewed
CVE-2021-46935
was published
Feb 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
fs/mount_setattr: always...
Moderate
Unreviewed
CVE-2021-46923
was published
Feb 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
locking/qrwlock: Fix...
Moderate
Unreviewed
CVE-2021-46921
was published
Feb 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
dmaengine: idxd: fix wq...
Moderate
Unreviewed
CVE-2021-46917
was published
Feb 27, 2024
In the Linux kernel, the following vulnerability has been resolved:
HID: usbhid: fix info leak...
Moderate
Unreviewed
CVE-2021-46906
was published
Feb 26, 2024
The Author Box, Guest Author and Co-Authors for Your Posts – Molongui plugin for WordPress is...
Moderate
Unreviewed
CVE-2023-7014
was published
Feb 6, 2024
IBM PowerSC 1.3, 2.0, and 2.1 may allow a remote attacker to view session identifiers passed via...
Low
Unreviewed
CVE-2023-50328
was published
Feb 2, 2024
An issue in Fronius Datalogger Web v.2.0.5-4, allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2023-37621
was published
Feb 1, 2024
containerd environment variable leak
Moderate
CVE-2021-21334
was published
for
github.com/containerd/containerd
(Go)
Jan 31, 2024
runc vulnerable to container breakout through process.cwd trickery and leaked fds
High
CVE-2024-21626
was published
for
github.com/opencontainers/runc
(Go)
Jan 31, 2024
The WP STAGING WordPress Backup plugin before 3.2.0 allows access to cache files during the...
High
Unreviewed
CVE-2023-7204
was published
Jan 29, 2024
An improper access control vulnerability exists in GitLab Remote Development affecting all...
Moderate
Unreviewed
CVE-2023-6955
was published
Jan 12, 2024
An Exposure of Resource to Wrong Sphere vulnerability in the Packet Forwarding Engine (PFE) of...
Moderate
Unreviewed
CVE-2024-21597
was published
Jan 12, 2024
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading...
Moderate
Unreviewed
CVE-2024-0443
was published
Jan 12, 2024
Windows CoreMessaging Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-20694
was published
Jan 9, 2024
ProTip!
Advisories are also available from the
GraphQL API