GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,901
Maven
5,000+
npm
3,631
NuGet
638
pip
3,244
Pub
10
RubyGems
863
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Check for xhci-...
Moderate
Unreviewed
CVE-2024-45027
was published
Sep 11, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/i915/gt: Cleanup partial...
Moderate
Unreviewed
CVE-2022-48893
was published
Aug 21, 2024
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible
Moderate
CVE-2020-10685
was published
for
ansible
(pip)
Apr 7, 2021
Vulnerability of resources not being closed or released in the keystore module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-45445
was published
Sep 4, 2024
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat
Moderate
CVE-2024-23672
was published
for
org.apache.tomcat.embed:tomcat-embed-websocket
(Maven)
Mar 13, 2024
Incomplete cleanup in Intel(R) Power Gadget software for macOS all versions may allow an...
Moderate
Unreviewed
CVE-2023-45846
was published
May 16, 2024
Apache Tomcat Incomplete Cleanup vulnerability
Moderate
CVE-2023-42795
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 10, 2023
Little Snitch versions 4.4.0 fixes a vulnerability in a privileged helper tool. However, the...
Moderate
Unreviewed
CVE-2019-13014
was published
May 24, 2022
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a...
Moderate
Unreviewed
CVE-2022-40974
was published
May 10, 2023
Pydio Cells before 1.5.0 does incomplete cleanup of a user's data upon deletion. This allows a...
Moderate
Unreviewed
CVE-2019-12902
was published
May 24, 2022
** UNSUPPORTED WHEN ASSIGNED ** In OSS-RC systems of the release 18B and older during data...
Moderate
Unreviewed
CVE-2021-32571
was published
May 24, 2022
An unauthenticated remote attacker can gain service level privileges through an incomplete...
Moderate
Unreviewed
CVE-2024-26005
was published
Mar 12, 2024
PGP 6.x and 7.x does not clear Windows alternate data streams that are attached to files on NTFS...
Moderate
Unreviewed
CVE-2002-2069
was published
Apr 30, 2022
Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file...
Moderate
Unreviewed
CVE-2002-2068
was published
Apr 30, 2022
SecureClean 3 build 2.0 does not clear Windows alternate data streams that are attached to files...
Moderate
Unreviewed
CVE-2002-2070
was published
Apr 30, 2022
East-Tec Eraser 2002 does not clear Windows alternate data streams that are attached to files on...
Moderate
Unreviewed
CVE-2002-2067
was published
Apr 30, 2022
BestCrypt BCWipe 1.0.7 and 2.0 through 2.35.1 does not clear Windows alternate data streams that...
Moderate
Unreviewed
CVE-2002-2066
was published
Apr 30, 2022
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged...
Moderate
Unreviewed
CVE-2021-46766
was published
Nov 14, 2023
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a...
Moderate
Unreviewed
CVE-2022-42310
was published
Nov 1, 2022
An Incomplete Cleanup vulnerability in Nonstop active routing (NSR) component of Juniper...
Moderate
Unreviewed
CVE-2024-21617
was published
Jan 12, 2024
Apache Tomcat Incomplete Cleanup vulnerability
Moderate
CVE-2023-42794
was published
for
org.apache.tomcat:tomcat
(Maven)
Oct 10, 2023
Spring Security logout not clearing security context
Moderate
CVE-2023-20862
was published
for
org.springframework.security:spring-security-core
(Maven)
Apr 19, 2023
redis-py Race Condition due to incomplete fix
Moderate
CVE-2023-28859
was published
for
redis
(pip)
Mar 26, 2023
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a...
Moderate
Unreviewed
CVE-2022-0171
was published
Aug 27, 2022
A vulnerability was found in the Linux kernel's KVM subsystem in arch/x86/kvm/lapic.c...
Moderate
Unreviewed
CVE-2021-4032
was published
Jan 22, 2022
ProTip!
Advisories are also available from the
GraphQL API