GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
14 advisories
Filter by severity
The Object Request Broker (ORB) in IBM SDK, Java Technology Edition 7.1.0.0 through 7.1.5.18 and...
Moderate
Unreviewed
CVE-2024-27267
was published
Aug 14, 2024
IBM QRadar Suite Products 1.10.12.0 through 1.10.18.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2023-47742
was published
Mar 3, 2024
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept...
Moderate
Unreviewed
CVE-2023-7008
was published
Dec 23, 2023
Man in the Middle vulnerability, which could allow an attacker to intercept VNF (Virtual Network...
Moderate
Unreviewed
CVE-2023-4885
was published
Oct 3, 2023
A Channel Accessible by Non-Endpoint vulnerability in the Schweitzer Engineering Laboratories SEL...
Moderate
Unreviewed
CVE-2023-2310
was published
May 10, 2023
curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to...
Moderate
Unreviewed
CVE-2021-22890
was published
May 24, 2022
containernetworking/plugins vulnerable to MitM attacks
Moderate
CVE-2020-10749
was published
for
github.com/containernetworking/plugins
(Go)
May 24, 2022
Missing SSH host key validation in Jenkins Amazon EC2 Plugin
Moderate
CVE-2020-2185
was published
for
org.jenkins-ci.plugins:ec2
(Maven)
May 24, 2022
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle...
Moderate
Unreviewed
CVE-2019-3981
was published
May 24, 2022
Jenkins Google Compute Engine Plugin does not verify SSH host keys when connecting agents created by the plugin
Moderate
CVE-2019-16546
was published
for
org.jenkins-ci.plugins:google-compute-engine
(Maven)
May 24, 2022
It was discovered that the fix for CVE-2017-12150 was not properly shipped in erratum RHSA-2017...
Moderate
Unreviewed
CVE-2017-15085
was published
May 13, 2022
Insecure Defaults Leads to Potential MITM in ezseed-transmission
Moderate
CVE-2016-1000224
was published
for
ezseed-transmission
(npm)
Sep 1, 2020
Machine-In-The-Middle in https-proxy-agent
Moderate
GHSA-pc5p-h8pf-mvwp
was published
for
https-proxy-agent
(npm)
Apr 16, 2020
Insecure Defaults Allow MITM Over TLS in engine.io-client
Moderate
CVE-2016-10536
was published
for
engine.io-client
(npm)
Feb 18, 2019
ProTip!
Advisories are also available from the
GraphQL API