GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
Moderate severity vulnerability that affects io.vertx:vertx-core
Moderate
CVE-2018-12537
was published
for
io.vertx:vertx-core
(Maven)
Oct 19, 2018
undici before v5.8.0 vulnerable to CRLF injection in request headers
Moderate
CVE-2022-31150
was published
for
undici
(npm)
Jul 21, 2022
Improper Neutralization of CRLF Sequences in Wildfly Undertow
Moderate
CVE-2016-4993
was published
for
org.wildfly:wildfly-undertow
(Maven)
May 17, 2022
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a CRLF...
Moderate
Unreviewed
CVE-2017-8788
was published
May 17, 2022
CRLF injection vulnerability in the url_parse function in url.c in Wget through 1.19.1 allows...
Moderate
Unreviewed
CVE-2017-6508
was published
May 17, 2022
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2...
Moderate
Unreviewed
CVE-2017-2111
was published
May 17, 2022
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote...
Moderate
Unreviewed
CVE-2017-5868
was published
May 17, 2022
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is a home/seos...
Moderate
Unreviewed
CVE-2017-8791
was published
May 17, 2022
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through...
Moderate
Unreviewed
CVE-2019-9947
was published
May 13, 2022
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through...
Moderate
Unreviewed
CVE-2019-9740
was published
May 13, 2022
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11...
High
Unreviewed
CVE-2018-19585
was published
May 24, 2022
undici before v5.8.0 vulnerable to uncleared cookies on cross-host / cross-origin redirect
Low
CVE-2022-31151
was published
for
undici
(npm)
Jul 21, 2022
CRLF injection vulnerability in phpMyVisites before 2.2 allows remote attackers to inject...
High
Unreviewed
CVE-2007-0892
was published
May 1, 2022
CRLF injection vulnerability in the web-based management (WBM) interface in Unify (former Siemens...
Moderate
Unreviewed
CVE-2014-9563
was published
May 13, 2022
Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir....
Moderate
Unreviewed
CVE-2016-4975
was published
May 13, 2022
An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker...
Moderate
Unreviewed
CVE-2019-9741
was published
May 13, 2022
phpservermon is vulnerable to CRLF Injection
Moderate
CVE-2021-4097
was published
for
phpservermon/phpservermon
(Composer)
Dec 16, 2021
A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote...
High
Unreviewed
CVE-2018-12477
was published
May 13, 2022
Ansible Tower as shipped with Red Hat CloudForms Management Engine 5 is vulnerable to CRLF...
Moderate
Unreviewed
CVE-2017-7528
was published
May 13, 2022
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
High
Unreviewed
CVE-2019-10678
was published
May 14, 2022
CRLF injection vulnerability in Infoblox Network Automation NetMRI before 7.1.1 allows remote...
Moderate
Unreviewed
CVE-2016-6484
was published
May 14, 2022
CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote...
Moderate
Unreviewed
CVE-2016-5331
was published
May 14, 2022
Insufficient restriction of IPP filters in CUPS in Google Chrome OS prior to 62.0.3202.74 allowed...
High
Unreviewed
CVE-2017-15400
was published
May 14, 2022
Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection via CRLF sequences in a...
Moderate
Unreviewed
CVE-2015-9096
was published
May 14, 2022
CRLF injection vulnerability in OXID eShop Professional Edition before 4.7.11 and 4.8.x before 4...
Moderate
Unreviewed
CVE-2014-2017
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API