GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
527 advisories
Filter by severity
In DevicePolicyManager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2021-39744
was published
Mar 31, 2022
In Framework, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39756
was published
Mar 31, 2022
In ContextImpl, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39754
was published
Mar 31, 2022
In DevicePolicyManager, there is a possible way to reveal the existence of an installed package...
Moderate
Unreviewed
CVE-2021-39755
was published
Mar 31, 2022
In Settings, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39766
was published
Mar 31, 2022
In Media, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39761
was published
Mar 31, 2022
In AudioService, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39760
was published
Mar 31, 2022
In VpnManagerService, there is a possible disclosure of installed VPN packages due to side...
Moderate
Unreviewed
CVE-2021-39773
was published
Mar 31, 2022
In People, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2021-39775
was published
Mar 31, 2022
In TelecomManager, there is a possible way to check if a particular self managed phone account...
Moderate
Unreviewed
CVE-2021-39788
was published
Mar 31, 2022
In WallpaperManagerService, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2021-39791
was published
Mar 31, 2022
Discoverability of user password hash in Statamic CMS
Low
CVE-2022-24784
was published
for
statamic/cms
(Composer)
Mar 29, 2022
Symfony Http-Kernel has non-constant time comparison in UriSigner
High
CVE-2019-18887
was published
for
symfony/http-kernel
(Composer)
Mar 26, 2022
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised...
High
Unreviewed
CVE-2020-36517
was published
Mar 11, 2022
The pointer-validation logic in util/mem_util.rs in Occlum before 0.26.0 for Intel SGX acts as a...
Moderate
Unreviewed
CVE-2021-44421
was published
Mar 11, 2022
A vulnerability has been identified in RUGGEDCOM ROS M2100 (All versions < V5.6.0), RUGGEDCOM ROS...
High
Unreviewed
CVE-2021-42016
was published
Mar 9, 2022
A vulnerability in Qlik Sense Enterprise on Windows could allow an remote attacker to enumerate...
Moderate
Unreviewed
CVE-2022-0564
was published
Feb 22, 2022
The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable...
Critical
Unreviewed
CVE-2022-23303
was published
Feb 15, 2022
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are...
Critical
Unreviewed
CVE-2022-23304
was published
Feb 15, 2022
Exposure of Sensitive Information in snipe/snipe-it
Moderate
CVE-2022-0569
was published
for
snipe/snipe-it
(Composer)
Feb 15, 2022
In isServiceDistractionOptimized of CarPackageManagerService.java, there is a possible disclosure...
Moderate
Unreviewed
CVE-2021-0524
was published
Feb 12, 2022
The password-reset form in ServiceNow Orlando provides different responses to invalid...
Moderate
Unreviewed
CVE-2021-45901
was published
Feb 11, 2022
Apache Hive Information Exposure and Observable Timing Discrepancy
Moderate
CVE-2020-1926
was published
for
org.apache.hive:hive
(Maven)
Feb 9, 2022
IBM Guardium Data Encryption (GDE) 5.0.0.2 behaves differently or sends different responses under...
Moderate
Unreviewed
CVE-2021-39021
was published
Feb 3, 2022
Observable Response Discrepancy in Flask-AppBuilder
Moderate
CVE-2022-21659
was published
for
Flask-AppBuilder
(pip)
Feb 1, 2022
ProTip!
Advisories are also available from the
GraphQL API