GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
21
Go
2,003
Maven
5,000+
npm
3,714
NuGet
661
pip
3,387
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
3,387 advisories
Filter by severity
Mitmweb in mitmproxy allows DNS Rebinding attacks
Critical
CVE-2018-14505
was published
for
mitmproxy
(pip)
Jul 31, 2018
Pillow Integer overflow in ImagingResampleHorizontal
Critical
CVE-2016-4009
was published
for
pillow
(pip)
Jul 24, 2018
Pillow Buffer overflow in ImagingFliDecode
High
CVE-2016-0775
was published
for
Pillow
(pip)
Jul 24, 2018
Pillow buffer overflow in ImagingPcdDecode
High
CVE-2016-2533
was published
for
pillow
(pip)
Jul 24, 2018
Pillow Buffer overflow in ImagingLibTiffDecode
Moderate
CVE-2016-0740
was published
for
pillow
(pip)
Jul 24, 2018
feedparser denial of service vulnerability
High
CVE-2012-2921
was published
for
feedparser
(pip)
Jul 24, 2018
Plone Cross-site Scripting vulnerability
Moderate
CVE-2011-1949
was published
for
Plone
(pip)
Jul 23, 2018
Plone and plone.app.users allow remote authenticated users to modify the properties of arbitrary accounts
High
CVE-2011-1950
was published
for
Plone
(pip)
Jul 23, 2018
Plone allows remote attackers to read hidden folder contents
High
CVE-2012-5503
was published
for
Plone
(pip)
Jul 23, 2018
feedparser Cross-site Scripting vulnerability
Moderate
CVE-2011-1157
was published
for
feedparser
(pip)
Jul 23, 2018
Plone and Zope2 vulnerable to unauthorized access to restricted attributes
High
CVE-2012-5489
was published
for
Plone
(pip)
Jul 23, 2018
High severity vulnerability that affects Plone and Zope2
High
CVE-2011-2528
was published
for
Plone
(pip)
Jul 23, 2018
HTTP header injection in Plone and Zope2
High
CVE-2012-5486
was published
for
Plone
(pip)
Jul 23, 2018
feedparser Cross-site Scripting vulnerability
Moderate
CVE-2011-1158
was published
for
feedparser
(pip)
Jul 23, 2018
Improper query string handling in Django
High
CVE-2010-4534
was published
for
Django
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Zope2
Moderate
CVE-2010-1104
was published
for
Zope2
(pip)
Jul 23, 2018
Django Cross-Site Request Forgery vulnerability
High
CVE-2011-4140
was published
for
Django
(pip)
Jul 23, 2018
ProTip!
Advisories are also available from the
GraphQL API