GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,262
Erlang
31
GitHub Actions
21
Go
2,024
Maven
5,000+
npm
3,731
NuGet
662
pip
3,407
Pub
12
RubyGems
891
Rust
864
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
48 advisories
Filter by severity
Inconsistent interpretation of HTTP requests ('HTTP Request/Response Smuggling') issue exists in...
Moderate
Unreviewed
CVE-2024-53008
was published
Nov 28, 2024
In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request...
Moderate
Unreviewed
CVE-2024-34535
was published
Oct 3, 2024
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can...
Moderate
Unreviewed
CVE-2024-24795
was published
Apr 4, 2024
A deep link validation issue in KakaoTalk 10.4.3 allowed a remote adversary to direct users to...
Moderate
Unreviewed
CVE-2023-51219
was published
Jun 3, 2024
An issue discovered in SELESTA Visual Access Manager 4.38.6 allows attackers to modify the ...
Moderate
Unreviewed
CVE-2023-50811
was published
Mar 20, 2024
Loway - CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Moderate
Unreviewed
CVE-2024-42342
was published
Sep 8, 2024
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite ...
Moderate
Unreviewed
CVE-2024-20915
was published
Feb 17, 2024
A vulnerability classified as critical was found in mhuertos phpLDAPadmin up to...
Moderate
Unreviewed
CVE-2016-15039
was published
Jul 11, 2024
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Apache...
Moderate
Unreviewed
CVE-2024-32638
was published
May 2, 2024
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an...
Moderate
Unreviewed
CVE-2024-22279
was published
Jun 10, 2024
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not...
Moderate
Unreviewed
CVE-2019-17567
was published
May 24, 2022
HPE MSA Controller prior to version IN210R004 could be remotely exploited to allow inconsistent...
Moderate
Unreviewed
CVE-2023-30910
was published
Oct 9, 2023
VMware Horizon Server contains a HTTP request smuggling vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2023-34037
was published
Aug 4, 2023
All versions of the package drogonframework/drogon are vulnerable to HTTP Response Splitting when...
Moderate
Unreviewed
CVE-2023-26137
was published
Jul 6, 2023
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco...
Moderate
Unreviewed
CVE-2019-15272
was published
May 24, 2022
Citrix Gateway 11.1, 12.0, and 12.1 has an Inconsistent Interpretation of HTTP Requests.
Moderate
Unreviewed
CVE-2020-10111
was published
May 24, 2022
Citrix Gateway 11.1, 12.0, and 12.1 allows Cache Poisoning.
Moderate
Unreviewed
CVE-2020-10112
was published
May 24, 2022
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling,...
Moderate
Unreviewed
CVE-2022-21826
was published
Oct 1, 2022
HTTP request smuggling vulnerability in Sun Java System Proxy Server before 20061130, when used...
Moderate
Unreviewed
CVE-2006-6276
was published
May 1, 2022
The Apache HTTP server before 1.3.34, and 2.0.x before 2.0.55, when acting as an HTTP proxy,...
Moderate
Unreviewed
CVE-2005-2088
was published
May 1, 2022
Microsoft IIS 5.0 and 6.0 allows remote attackers to poison the web cache, bypass web application...
Moderate
Unreviewed
CVE-2005-2089
was published
May 1, 2022
SAP Fiori launchpad - versions SAP_UI 750, SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI...
Moderate
Unreviewed
CVE-2023-49584
was published
Dec 12, 2023
A vulnerability in the Clientless SSL VPN (WebVPN) component of Cisco Adaptive Security Appliance...
Moderate
Unreviewed
CVE-2022-20713
was published
Aug 11, 2022
SAP Web Dispatcher and Internet Communication Manager (ICM), versions - KRNL32NUC 7.21, 7.21EXT,...
Moderate
Unreviewed
CVE-2021-33683
was published
May 24, 2022
This vulnerability occurs when a web server fails to correctly process the Content-Length of POST...
Moderate
Unreviewed
CVE-2022-38114
was published
Nov 23, 2022
ProTip!
Advisories are also available from the
GraphQL API