GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
24,166 advisories
Filter by severity
An issue was discovered in Ovidentia 8.3. The file upload feature does not prevent the uploading...
Critical
Unreviewed
CVE-2022-41573
was published
Jan 7, 2025
I, Librarian before and including 5.11.1 is vulnerable to Server-Side Request Forgery (SSRF) due...
Critical
Unreviewed
CVE-2024-54819
was published
Jan 7, 2025
An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and...
Critical
Unreviewed
CVE-2024-35532
was published
Jan 7, 2025
A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which...
Critical
Unreviewed
CVE-2024-55414
was published
Jan 7, 2025
File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50660
was published
Jan 7, 2025
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to...
Critical
Unreviewed
CVE-2024-50658
was published
Jan 7, 2025
A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the...
Critical
Unreviewed
CVE-2024-55556
was published
Jan 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP...
Critical
Unreviewed
CVE-2024-56278
was published
Jan 7, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56284
was published
Jan 7, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56290
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object...
Critical
Unreviewed
CVE-2024-49222
was published
Jan 7, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing...
Critical
Unreviewed
CVE-2024-43243
was published
Jan 7, 2025
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2024-12470
was published
Jan 7, 2025
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a...
Critical
Unreviewed
CVE-2024-8855
was published
Jan 7, 2025
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing...
Critical
Unreviewed
CVE-2024-12252
was published
Jan 7, 2025
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all...
Critical
Unreviewed
CVE-2024-12264
was published
Jan 7, 2025
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is...
Critical
Unreviewed
CVE-2024-12402
was published
Jan 7, 2025
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software...
Critical
Unreviewed
CVE-2024-46622
was published
Jan 6, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54879
was published
Jan 6, 2025
SeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an...
Critical
Unreviewed
CVE-2024-54880
was published
Jan 6, 2025
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
Critical
Unreviewed
CVE-2024-55529
was published
Jan 6, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to...
Critical
Unreviewed
CVE-2024-5594
was published
Jan 6, 2025
In wlan STA FW, there is a possible out of bounds write due to improper input validation. This...
Critical
Unreviewed
CVE-2024-20148
was published
Jan 6, 2025
ProTip!
Advisories are also available from the
GraphQL API