GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
10,772 advisories
Filter by severity
Improper Input Validation in Apache Tomcat
Moderate
CVE-2014-0227
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Input Validation in Apache POI
Moderate
CVE-2014-3574
was published
for
org.apache.poi:poi
(Maven)
May 17, 2022
Improper Input Validation vulnerability in Saturday Drive Ninja Forms Contact Form.This issue...
Moderate
Unreviewed
CVE-2023-36505
was published
Apr 17, 2024
Server receiving a malformed message to create a new connection could lead to an attacker...
High
Unreviewed
CVE-2023-5397
was published
Apr 17, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-3646
was published
Apr 19, 2024
Moodle arbitrary file read vulnerability
Moderate
CVE-2023-28330
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Improper Input Validation in Jetty
Moderate
CVE-2011-4461
was published
for
org.eclipse.jetty:jetty-server
(Maven)
May 14, 2022
.NET Framework Denial of Service Vulnerability
High
Unreviewed
CVE-2024-21312
was published
Jan 9, 2024
memory corruption in modem due to improper check while calculating size of serialized CoAP message
Critical
Unreviewed
CVE-2022-33211
was published
Apr 13, 2023
Memory corruption in Trusted Execution Environment while calling service API with invalid address.
High
Unreviewed
CVE-2023-21627
was published
Aug 8, 2023
Memory Corruption in HLOS while registering for key provisioning notify.
High
Unreviewed
CVE-2023-24853
was published
Oct 3, 2023
Transient DOS due to improper input validation in WLAN Host while parsing frame during...
High
Unreviewed
CVE-2022-34146
was published
Feb 12, 2023
Transient DOS while decoding message of size that exceeds the available system memory.
High
Unreviewed
CVE-2024-21453
was published
Apr 1, 2024
Memory corruption in core services when Diag handler receives a command to configure event...
High
Unreviewed
CVE-2023-28574
was published
Nov 14, 2023
Contao Insert tag injection in forms
Moderate
CVE-2020-25768
was published
for
contao/contao
(Composer)
Sep 24, 2020
Insufficient validation when decoding a Socket.IO packet
Critical
CVE-2022-2421
was published
for
socket.io-parser
(npm)
Oct 26, 2022
The systool_server in PAX Technology A930 PayDroid 7.1.1 Virgo V04.4.02 20211201 fails to check...
High
Unreviewed
CVE-2022-26582
was published
Dec 17, 2022
Drupal Denial of service via transliterate mechanism
Moderate
CVE-2016-9452
was published
for
drupal/core
(Composer)
May 17, 2022
Drupal file REST resource does not properly validate
Moderate
CVE-2017-6921
was published
for
drupal/core
(Composer)
May 13, 2022
Magento Improper input validation vulnerability
High
CVE-2022-42344
was published
for
magento/community-edition
(Composer)
Oct 20, 2022
Apache Tomcat may reject request containing invalid Content-Length header
High
CVE-2022-42252
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 1, 2022
Drupal Core Remote Code Execution Vulnerability
Critical
CVE-2018-7600
was published
for
drupal/core
(Composer)
May 14, 2022
Moodle PostScript Code Injection
Critical
CVE-2022-35649
was published
for
moodle/moodle
(Composer)
Jul 26, 2022
ProTip!
Advisories are also available from the
GraphQL API