GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
281 advisories
Filter by severity
The LIST_POISON feature in include/linux/poison.h in the Linux kernel before 4.3, as used in...
Moderate
Unreviewed
CVE-2016-0821
was published
May 13, 2022
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG...
Moderate
Unreviewed
CVE-2018-6982
was published
May 13, 2022
VMware ESXi 6.5 without patch ESXi650-201703410-SG, 6.0 U3 without patch ESXi600-201703401-SG, 6...
Moderate
Unreviewed
CVE-2017-4905
was published
May 13, 2022
VMware ESXi 6.7 without ESXi670-201811401-BG and VMware ESXi 6.5 without ESXi650-201811301-BG,...
High
Unreviewed
CVE-2018-6981
was published
May 13, 2022
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1995
was published
May 13, 2022
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1256
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-3345
was published
May 13, 2022
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-3343
was published
May 13, 2022
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2010-3346
was published
May 13, 2022
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1250
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-2559
was published
May 13, 2022
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1963
was published
May 13, 2022
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1254
was published
May 13, 2022
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1261
was published
May 13, 2022
Microsoft Internet Explorer 6, 7, and 8 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2010-2556
was published
May 13, 2022
Microsoft Internet Explorer 6 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1964
was published
May 13, 2022
Microsoft Internet Explorer 9 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2011-1998
was published
May 13, 2022
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Mac, Windows,...
Moderate
Unreviewed
CVE-2017-5102
was published
May 13, 2022
An issue was discovered in the EXIF component in PHP before 7.1.27, 7.2.x before 7.2.16, and 7.3...
Critical
Unreviewed
CVE-2019-9641
was published
May 13, 2022
Microsoft Internet Explorer 7 through 9 does not properly handle objects in memory, which allows...
High
Unreviewed
CVE-2011-1262
was published
May 13, 2022
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2011-1251
was published
May 13, 2022
The Vector Markup Language (VML) implementation in vgx.dll in Microsoft Internet Explorer 6...
High
Unreviewed
CVE-2011-1266
was published
May 13, 2022
The Timed Interactive Multimedia Extensions (aka HTML+TIME) implementation in Microsoft Internet...
High
Unreviewed
CVE-2011-1255
was published
May 13, 2022
Use of an uninitialized value in Skia in Google Chrome prior to 60.0.3112.78 for Linux, Windows,...
Moderate
Unreviewed
CVE-2017-5103
was published
May 13, 2022
Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote...
High
Unreviewed
CVE-2010-2557
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API