GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
4,018 advisories
Filter by severity
A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic....
Moderate
Unreviewed
CVE-2025-0295
was published
Jan 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP...
Critical
Unreviewed
CVE-2024-56278
was published
Jan 7, 2025
The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator...
High
Unreviewed
CVE-2024-12471
was published
Jan 7, 2025
The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12419
was published
Jan 7, 2025
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing...
Critical
Unreviewed
CVE-2024-12252
was published
Jan 7, 2025
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
Critical
Unreviewed
CVE-2024-55529
was published
Jan 6, 2025
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29404
was published
Jun 8, 2023
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file...
Moderate
Unreviewed
CVE-2023-6601
was published
Jan 6, 2025
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage...
Moderate
Unreviewed
CVE-2023-6604
was published
Jan 6, 2025
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1...
Critical
Unreviewed
CVE-2023-35034
was published
Jun 12, 2023
A potential security vulnerability has been identified with a version of the HP Softpaq installer...
High
Unreviewed
CVE-2019-16283
was published
Jun 9, 2023
D-Link DIR-806 devices allow remote attackers to execute arbitrary shell commands via a trailing...
Critical
Unreviewed
CVE-2019-10891
was published
May 24, 2022
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-11733
was published
Jan 4, 2025
Server Side Template Injection (SSTI) via Twig escape handler
High
CVE-2024-28119
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
Server Side Template Injection (SSTI)
High
CVE-2024-28118
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
Server Side Template Injection (SSTI)
High
CVE-2024-28117
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
.NET Remote Code Execution Vulnerability
High
CVE-2022-41089
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Dec 14, 2022
Apache MINA Deserialization RCE Vulnerability
Critical
CVE-2024-52046
was published
for
org.apache.mina:mina-core
(Maven)
Dec 25, 2024
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability. This CVE ID is...
High
Unreviewed
CVE-2022-37982
was published
Oct 12, 2022
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2022-30141
was published
Jun 16, 2022
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability.
High
Unreviewed
CVE-2022-30145
was published
Jun 16, 2022
Windows Fax Service Remote Code Execution Vulnerability.
High
Unreviewed
CVE-2022-29115
was published
May 11, 2022
Loomio version 2.22.0 allows executing arbitrary commands on the server.
This is possible...
Critical
Unreviewed
CVE-2024-1297
was published
Feb 20, 2024
The The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12238
was published
Dec 29, 2024
An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2024-50715
was published
Dec 27, 2024
ProTip!
Advisories are also available from the
GraphQL API