GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
86 advisories
Filter by severity
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM...
High
Unreviewed
CVE-2023-3581
was published
Jul 17, 2023
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution...
High
Unreviewed
CVE-2019-19019
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep...
High
Unreviewed
CVE-2019-16235
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep...
High
Unreviewed
CVE-2019-16237
was published
May 24, 2022
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content...
High
Unreviewed
CVE-2019-9803
was published
May 24, 2022
MeshCentral cross-site websocket hijacking (CSWSH) vulnerability
High
CVE-2024-26135
was published
for
meshcentral
(npm)
Feb 21, 2024
The default configuration for the domain name resolver for Microsoft Windows 98, NT 4.0, 2000,...
High
Unreviewed
CVE-2000-1218
was published
Apr 30, 2022
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47193
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47198
was published
Jan 23, 2024
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent...
High
Unreviewed
CVE-2023-47200
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47194
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47195
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47197
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47196
was published
Jan 23, 2024
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local...
High
Unreviewed
CVE-2023-47199
was published
Jan 23, 2024
Backend Same-Site Request Forgery in TYPO3 CMS
High
CVE-2020-11069
was published
for
typo3/cms
(Composer)
May 13, 2020
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...
High
Unreviewed
CVE-2020-16952
was published
May 24, 2022
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to...
High
Unreviewed
CVE-2020-16951
was published
May 24, 2022
CardGate Payments plugin for WooCommerce does not validate request origin
High
CVE-2020-8819
was published
for
cardgate/woocommerce
(Composer)
May 24, 2022
HashiCorp Consul vulnerable to Origin Validation Error
High
CVE-2019-9764
was published
for
github.com/hashicorp/consul
(Go)
May 13, 2022
RubyGems has Origin Validation Error vulnerability
High
CVE-2017-0902
was published
for
rubygems-update
(RubyGems)
May 13, 2022
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which...
High
Unreviewed
CVE-2009-1185
was published
May 2, 2022
A vulnerability exists during the installation of add-ons where the initial fetch ignored the...
High
Unreviewed
CVE-2019-11723
was published
May 24, 2022
Response header name interning does not have same-origin protections and these headers are stored...
High
Unreviewed
CVE-2017-7797
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API