GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,081
Erlang
29
GitHub Actions
19
Go
1,909
Maven
5,000+
npm
3,642
NuGet
638
pip
3,259
Pub
10
RubyGems
869
Rust
820
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
282 advisories
Filter by severity
In ContentService, there is a possible way to read installed sync content providers due to side...
Moderate
Unreviewed
CVE-2023-21306
was published
Oct 30, 2023
In InputMethod, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21331
was published
Oct 30, 2023
In PackageManagerNative, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2023-21293
was published
Oct 30, 2023
In Permission, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21296
was published
Oct 30, 2023
In Content, here is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21303
was published
Oct 30, 2023
In Package Manager Service, there is a possible way to determine whether an app is installed,...
Moderate
Unreviewed
CVE-2023-21326
was published
Oct 30, 2023
In Overlay Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21330
was published
Oct 30, 2023
In Content, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21316
was published
Oct 30, 2023
In Activity Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21323
was published
Oct 30, 2023
In Settings, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21325
was published
Oct 30, 2023
In Content, there is a possible way to determine whether an app is installed, without query...
Moderate
Unreviewed
CVE-2023-21318
was published
Oct 30, 2023
In Permission Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21327
was published
Oct 30, 2023
In Usage Stats Service, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2022-20264
was published
Oct 30, 2023
In Package Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21299
was published
Oct 30, 2023
In Package Manager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21302
was published
Oct 30, 2023
In PackageManager, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21300
was published
Oct 30, 2023
In ContentService, there is a possible way to determine whether an app is installed, without...
Moderate
Unreviewed
CVE-2023-21317
was published
Oct 30, 2023
Using iterative requests an attacker was able to learn the size of an opaque response, as well as...
Moderate
Unreviewed
CVE-2023-5722
was published
Oct 25, 2023
The AES implementation in the Texas Instruments OMAP L138 (secure variants), present in mask ROM,...
Moderate
Unreviewed
CVE-2022-25332
was published
Oct 19, 2023
A vulnerability has been identified in Mendix Forgot Password (Mendix 10 compatible) (All...
Moderate
Unreviewed
CVE-2023-43623
was published
Oct 10, 2023
PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software...
Moderate
Unreviewed
CVE-2023-44216
was published
Sep 27, 2023
User enumeration vulnerability in Arconte Áurea 1.5.0.0 version. The exploitation of this...
Moderate
Unreviewed
CVE-2023-4095
was published
Sep 19, 2023
User enumeration vulnerability in Password Recovery plugin 1.2 version for Roundcube, which could...
Moderate
Unreviewed
CVE-2023-3221
was published
Sep 4, 2023
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the...
Moderate
Unreviewed
CVE-2023-20569
was published
Aug 8, 2023
A potential power side-channel vulnerability in
AMD processors may allow an authenticated...
Moderate
Unreviewed
CVE-2023-20583
was published
Aug 1, 2023
ProTip!
Advisories are also available from the
GraphQL API