GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
414 advisories
Filter by severity
SMTP smuggling in Apache James
High
CVE-2023-51747
was published
for
org.apache.james:james-server
(Maven)
Feb 27, 2024
Topydo Improper Input Validation vulnerability
High
CVE-2018-1000523
was published
for
topydo
(pip)
Sep 13, 2018
Incomplete validation in MKL requantization
High
CVE-2021-37665
was published
for
tensorflow
(pip)
Aug 25, 2021
Incomplete validation in `QuantizeV2`
High
CVE-2021-37663
was published
for
tensorflow
(pip)
Aug 25, 2021
Drupal has open redirect vulnerability in the Overlay module
High
CVE-2013-6389
was published
for
drupal/drupal
(Composer)
May 17, 2022
Segmentation fault in tensorflow-lite
High
CVE-2020-15210
was published
for
tensorflow
(pip)
Sep 25, 2020
Improper Input Validation in Google TensorFlow
High
CVE-2018-7577
was published
for
tensorflow
(pip)
Apr 30, 2019
SaltStack Salt is vulnerable Arbitrary Directory Access
High
CVE-2020-11652
was published
for
salt
(pip)
May 24, 2022
PyWBEM TOCTOU vulnerability in certificate validation
High
CVE-2013-6418
was published
for
pywbem
(pip)
May 17, 2022
python-gnupg's shell_quote function does not properly quote strings
High
CVE-2014-1927
was published
for
python-gnupg
(pip)
Nov 6, 2018
Improper Input Validation in sopel-plugins.channelmgnt
High
CVE-2021-21431
was published
for
sopel-plugins.channelmgnt
(pip)
Apr 9, 2021
Apache Qpid Python client Improper certificate validation
High
CVE-2013-1909
was published
for
qpid-python
(pip)
May 13, 2022
python-gnupg's shell_quote function does not properly escape characters
High
CVE-2014-1928
was published
for
python-gnupg
(pip)
Nov 6, 2018
python-bugzilla has improper validation of X.509 certificates
High
CVE-2013-2191
was published
for
python-bugzilla
(pip)
May 14, 2022
python-glanceclient vulnerable to SSL server spoofing due to unverified X.509 certificate
High
CVE-2013-4111
was published
for
python-glanceclient
(pip)
May 14, 2022
PyOpenSSL Mishandles NUL Byte In Certificate Subject Alternative Name
High
CVE-2013-4314
was published
for
pyOpenSSL
(pip)
May 17, 2022
SaltStack Salt Denial of Service via a crafted authentication request
High
CVE-2017-14696
was published
for
salt
(pip)
May 17, 2022
Improper Input Validation in pyftpdlib
High
CVE-2007-6739
was published
for
pyftpdlib
(pip)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API