GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
912 advisories
Filter by severity
A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic....
Moderate
Unreviewed
CVE-2025-0295
was published
Jan 7, 2025
The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12419
was published
Jan 7, 2025
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file...
Moderate
Unreviewed
CVE-2023-6601
was published
Jan 6, 2025
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage...
Moderate
Unreviewed
CVE-2023-6604
was published
Jan 6, 2025
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12238
was published
Dec 29, 2024
Delinea addressed a reported case on Secret Server v11.7.31 (protocol handler version 6.0.3.26)...
Moderate
Unreviewed
CVE-2024-12908
was published
Dec 26, 2024
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as...
Moderate
Unreviewed
CVE-2024-37773
was published
Dec 17, 2024
The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2024-11012
was published
Dec 13, 2024
The The WPMobile.App — Android and iOS Mobile Application plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12420
was published
Dec 13, 2024
The The Simple Link Directory plugin for WordPress is vulnerable to arbitrary shortcode execution...
Moderate
Unreviewed
CVE-2024-12417
was published
Dec 13, 2024
The The Coupon Affiliates – Affiliate Plugin for WooCommerce plugin for WordPress is vulnerable...
Moderate
Unreviewed
CVE-2024-12421
was published
Dec 13, 2024
An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an...
Moderate
Unreviewed
CVE-2024-55918
was published
Dec 13, 2024
The Woodmart theme for WordPress is vulnerable to arbitrary shortcode execution in all versions...
Moderate
Unreviewed
CVE-2024-12333
was published
Dec 12, 2024
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue...
Moderate
Unreviewed
CVE-2024-12350
was published
Dec 9, 2024
The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via...
Moderate
Unreviewed
CVE-2024-10909
was published
Dec 6, 2024
The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User...
Moderate
Unreviewed
CVE-2024-10681
was published
Dec 6, 2024
The The InPost Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution via...
Moderate
Unreviewed
CVE-2024-11002
was published
Nov 26, 2024
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in...
Moderate
Unreviewed
CVE-2024-10262
was published
Nov 16, 2024
An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute...
Moderate
Unreviewed
CVE-2024-51330
was published
Nov 15, 2024
dom-iterator code execution vulnerability
Moderate
CVE-2024-21541
was published
for
dom-iterator
(npm)
Nov 13, 2024
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session...
Moderate
Unreviewed
CVE-2024-8069
was published
Nov 12, 2024
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6...
Moderate
Unreviewed
CVE-2024-46965
was published
Nov 11, 2024
Langflow vulnerable to remote code execution
Moderate
CVE-2024-48061
was published
for
langflow
(pip)
Nov 5, 2024
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the...
Moderate
Unreviewed
CVE-2024-10505
was published
Oct 30, 2024
CycloneDX cdxgen may execute code contained within build-related files
Moderate
CVE-2024-50611
was published
for
@cyclonedx/cdxgen
(npm)
Oct 28, 2024
ProTip!
Advisories are also available from the
GraphQL API