GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,133
Erlang
29
GitHub Actions
19
Go
1,940
Maven
5,000+
npm
3,677
NuGet
645
pip
3,295
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
456 advisories
Filter by severity
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability.
Critical
Unreviewed
CVE-2023-26785
was published
Oct 18, 2024
An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-23742
was published
Jan 28, 2024
The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries...
Critical
Unreviewed
CVE-2024-9264
was published
Oct 18, 2024
Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the...
Critical
Unreviewed
CVE-2023-50808
was published
Feb 13, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in Sunjianle allows Code...
Critical
Unreviewed
CVE-2024-49254
was published
Oct 16, 2024
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link...
Critical
Unreviewed
CVE-2024-48168
was published
Oct 14, 2024
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions...
Critical
Unreviewed
CVE-2023-32626
was published
Aug 18, 2023
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-45873
was published
Oct 8, 2024
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code ...
Critical
Unreviewed
CVE-2024-45874
was published
Oct 8, 2024
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code...
Critical
Unreviewed
CVE-2024-46076
was published
Oct 7, 2024
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925...
Critical
Unreviewed
CVE-2023-31447
was published
Aug 21, 2023
An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-41651
was published
Aug 12, 2024
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
Critical
Unreviewed
CVE-2024-45186
was published
Oct 2, 2024
Installer RCE on settings file write in MyBB before 1.8.22.
Critical
Unreviewed
CVE-2020-22612
was published
Sep 1, 2023
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and...
Critical
Unreviewed
CVE-2024-6386
was published
Aug 21, 2024
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an...
Critical
Unreviewed
CVE-2024-22127
was published
Mar 12, 2024
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at...
Critical
Unreviewed
CVE-2023-43234
was published
Sep 27, 2023
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
Critical
Unreviewed
CVE-2023-43222
was published
Sep 27, 2023
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
Critical
Unreviewed
CVE-2024-46103
was published
Sep 20, 2024
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although...
Critical
Unreviewed
CVE-2024-46640
was published
Sep 20, 2024
A condition exists in FlashArray Purity whereby an user with array admin role can execute...
Critical
Unreviewed
CVE-2024-0004
was published
Sep 23, 2024
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted...
Critical
Unreviewed
CVE-2023-44011
was published
Oct 3, 2023
Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww...
Critical
Unreviewed
CVE-2024-7104
was published
Sep 16, 2024
SQL Injection vulnerability in Best Free Law Office Management Software-v1.0 allows an attacker...
Critical
Unreviewed
CVE-2024-44430
was published
Sep 13, 2024
A remote code execution issue exists in HPE OneView.
Critical
Unreviewed
CVE-2023-30912
was published
Oct 25, 2023
ProTip!
Advisories are also available from the
GraphQL API