GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,835
Erlang
29
GitHub Actions
16
Go
1,715
Maven
4,950
npm
3,480
NuGet
605
pip
3,024
Pub
10
RubyGems
832
Rust
776
Swift
34
Unreviewed advisories
All unreviewed
5,000+
179 advisories
Filter by severity
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker...
Moderate
Unreviewed
CVE-2019-1613
was published
May 13, 2022
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by...
Critical
Unreviewed
CVE-2019-3463
was published
May 13, 2022
University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other...
High
Unreviewed
CVE-2018-19518
was published
May 13, 2022
An exploitable vulnerability exists in the smart cameras RTSP configuration of the Samsung...
Critical
Unreviewed
CVE-2018-3856
was published
May 13, 2022
An argument injection vulnerability in the browser-based authentication component of the...
High
Unreviewed
CVE-2022-29971
was published
May 10, 2022
An argument injection vulnerability in the browser-based authentication component of the...
High
Unreviewed
CVE-2022-30239
was published
May 10, 2022
An argument injection vulnerability in the browser-based authentication component of the...
High
Unreviewed
CVE-2022-29972
was published
May 10, 2022
An argument injection vulnerability in the browser-based authentication component of the...
High
Unreviewed
CVE-2022-30240
was published
May 10, 2022
Argument injection in python-libnmap
Critical
CVE-2022-30284
was published
for
python-libnmap
(pip)
May 6, 2022
Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to...
Moderate
Unreviewed
CVE-2006-6597
was published
May 1, 2022
Argument injection vulnerability in the Windows Object Packager (packager.exe) in Microsoft...
Moderate
Unreviewed
CVE-2006-4692
was published
May 1, 2022
Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or...
High
Unreviewed
CVE-2006-3015
was published
May 1, 2022
Argument injection vulnerability in the URI handler in Skype 2.0.*.104 and 2.5.*.0 through 2.5.*...
Low
Unreviewed
CVE-2006-2312
was published
May 1, 2022
Argument injection vulnerability in Microsoft Outlook 2003 SP1 allows user-assisted remote...
Moderate
Unreviewed
CVE-2006-2055
was published
May 1, 2022
Argument injection vulnerability in Avant Browser 10.1 Build 17 allows user-assisted remote...
Moderate
Unreviewed
CVE-2006-2058
was published
May 1, 2022
Argument injection vulnerability in Mozilla Firefox 1.0.6 allows user-assisted remote attackers...
Moderate
Unreviewed
CVE-2006-2057
was published
May 1, 2022
Argument injection vulnerability in Internet Explorer 6 for Windows XP SP2 allows user-assisted...
Moderate
Unreviewed
CVE-2006-2056
was published
May 1, 2022
Argument injection vulnerability in Beagle before 0.2.5 allows attackers to execute arbitrary...
High
Unreviewed
CVE-2006-1865
was published
May 1, 2022
Argument injection vulnerability in TellMe 1.2 and earlier allows remote attackers to modify...
Moderate
Unreviewed
CVE-2005-4699
was published
May 1, 2022
Internet Explorer 6 and earlier, when used with the Telnet client in Services for Unix (SFU) 2.0,...
High
Unreviewed
CVE-2001-0667
was published
Apr 30, 2022
Internet Explorer 5.5 and earlier executes Telnet sessions using command line arguments that are...
Moderate
Unreviewed
CVE-2001-0150
was published
Apr 30, 2022
Some implementations of rlogin allow root access if given a -froot parameter.
High
Unreviewed
CVE-1999-0113
was published
Apr 30, 2022
Argument injection vulnerability in the SSH URI handler for Safari on Mac OS 10.3.3 and earlier...
High
Unreviewed
CVE-2004-0489
was published
Apr 29, 2022
Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to...
High
Unreviewed
CVE-2004-0480
was published
Apr 29, 2022
Argument injection vulnerability in Opera before 7.50 does not properly filter "-" characters...
Low
Unreviewed
CVE-2004-0473
was published
Apr 29, 2022
ProTip!
Advisories are also available from the
GraphQL API