GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,752
Maven
4,982
npm
3,516
NuGet
609
pip
3,090
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
1,444 advisories
Filter by severity
Moderate severity vulnerability that affects Plone and plone.app.users
Moderate
CVE-2011-1950
was published
for
Plone
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects feedparser
Moderate
CVE-2012-2921
was published
for
feedparser
(pip)
Jul 24, 2018
Pillow Buffer overflow in ImagingLibTiffDecode
Moderate
CVE-2016-0740
was published
for
Pillow
(pip)
Jul 24, 2018
Pillow buffer overflow in ImagingPcdDecode
Moderate
CVE-2016-2533
was published
for
Pillow
(pip)
Jul 24, 2018
Pillow Buffer overflow in ImagingFliDecode
Moderate
CVE-2016-0775
was published
for
Pillow
(pip)
Jul 24, 2018
Moderate severity vulnerability that affects mayan-edms
Moderate
CVE-2018-16405
was published
for
mayan-edms
(pip)
Sep 6, 2018
Moderate severity vulnerability that affects mayan-edms
Moderate
CVE-2018-16406
was published
for
mayan-edms
(pip)
Sep 6, 2018
Moderate severity vulnerability that affects mayan-edms
Moderate
CVE-2018-16407
was published
for
mayan-edms
(pip)
Sep 6, 2018
Moderate severity vulnerability that affects mailman
Moderate
CVE-2018-13796
was published
for
mailman
(pip)
Sep 11, 2018
aiohttp-session Session Fixation vulnerability
Moderate
CVE-2018-1000519
was published
for
aiohttp-session
(pip)
Sep 13, 2018
Qutebrowser XSS Vulnerability
Moderate
CVE-2018-1000559
was published
for
qutebrowser
(pip)
Sep 13, 2018
Django allows unprivileged users to read the password hashes of arbitrary accounts
Moderate
CVE-2018-16984
was published
for
django
(pip)
Oct 3, 2018
Pyopenssl Incorrect Memory Management
Moderate
CVE-2018-1000808
was published
for
pyopenssl
(pip)
Oct 10, 2018
In marshmallow library the schema "only" option treats an empty list as implying no "only" option
Moderate
CVE-2018-17175
was published
for
marshmallow
(pip)
Oct 10, 2018
Ansible exposes sensitive data in log files and on the terminal
Moderate
CVE-2018-10855
was published
for
ansible
(pip)
Oct 10, 2018
Improper Input Validation in ansible
Moderate
CVE-2016-8647
was published
for
ansible
(pip)
Oct 10, 2018
Ansible does not verify that the server hostname matches a domain name in certificates
Moderate
CVE-2015-3908
was published
for
ansible
(pip)
Oct 10, 2018
python-gnupg vulnerable to shell injection
Moderate
CVE-2014-1929
was published
for
python-gnupg
(pip)
Nov 6, 2018
Moderate severity vulnerability that affects python-gnupg
Moderate
CVE-2014-1928
was published
for
python-gnupg
(pip)
Nov 6, 2018
Jupyter Notebook XSS via untrusted notebooks
Moderate
CVE-2018-19351
was published
for
notebook
(pip)
Nov 21, 2018
ProTip!
Advisories are also available from the
GraphQL API