GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
117,919 advisories
Filter by severity
Improper buffer restrictions in Intel(R) Media SDK all versions may allow an authenticated user...
Moderate
Unreviewed
CVE-2023-45221
was published
May 16, 2024
Uncontrolled search path for some Intel(R) CST software before version 2.1.10300 may allow an...
Moderate
Unreviewed
CVE-2023-40155
was published
May 16, 2024
Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an...
Moderate
Unreviewed
CVE-2023-41961
was published
May 16, 2024
Incorrect default permissions in some onboard video driver software before version 1.14 for Intel...
Moderate
Unreviewed
CVE-2023-42668
was published
May 16, 2024
Incorrect default permissions in some Endurance Gaming Mode software installers before version 1...
Moderate
Unreviewed
CVE-2023-42433
was published
May 16, 2024
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may...
Moderate
Unreviewed
CVE-2023-39929
was published
May 16, 2024
NULL pointer dereference in Intel(R) Power Gadget software for Windows all versions may allow an...
Moderate
Unreviewed
CVE-2023-41234
was published
May 16, 2024
Race condition for some some Intel(R) PROSet/Wireless WiFi software for Windows before version 23...
Moderate
Unreviewed
CVE-2023-40536
was published
May 16, 2024
Improper access control for some Intel(R) CST software before version 2.1.10300 may allow an...
Moderate
Unreviewed
CVE-2023-39433
was published
May 16, 2024
Null pointer dereference for some Intel(R) CST software before version 2.1.10300 may allow an...
Moderate
Unreviewed
CVE-2023-41082
was published
May 16, 2024
Improper access control in some Intel(R) CST before version 2.1.10300 may allow an authenticated...
Moderate
Unreviewed
CVE-2023-43487
was published
May 16, 2024
Improper conditions check in some Intel(R) BIOS PPAM firmware may allow a privileged user to...
Moderate
Unreviewed
CVE-2023-28383
was published
May 16, 2024
Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow...
Moderate
Unreviewed
CVE-2023-35192
was published
May 16, 2024
Improper input validation for some Intel(R) PROSet/Wireless WiFi software before version 23.20...
Moderate
Unreviewed
CVE-2023-38417
was published
May 16, 2024
Improper input validation of EpsdSrMgmtConfig in UEFI firmware for some Intel(R) Server Board...
Moderate
Unreviewed
CVE-2023-22662
was published
May 16, 2024
Issue summary: Checking excessively long DSA keys or parameters may be very
slow.
Impact summary...
Moderate
Unreviewed
CVE-2024-4603
was published
May 16, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-34805
was published
May 16, 2024
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2024-34808
was published
May 16, 2024
IBM Security Guardium 12.0 could allow a privileged user to perform unauthorized actions that...
Moderate
Unreviewed
CVE-2023-47717
was published
May 16, 2024
Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for...
Moderate
Unreviewed
CVE-2024-34751
was published
May 16, 2024
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')...
Moderate
Unreviewed
CVE-2024-34760
was published
May 16, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint
Moderate
CVE-2024-35185
was published
for
github.com/stacklok/minder
(Go)
May 16, 2024
REXML contains a denial of service vulnerability
Moderate
CVE-2024-35176
was published
for
rexml
(RubyGems)
May 16, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component...
Moderate
Unreviewed
CVE-2024-34958
was published
May 16, 2024
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component...
Moderate
Unreviewed
CVE-2024-34957
was published
May 16, 2024
ProTip!
Advisories are also available from the
GraphQL API