GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,474
Erlang
33
GitHub Actions
24
Go
2,198
Maven
5,000+
npm
3,843
NuGet
696
pip
3,632
Pub
12
RubyGems
911
Rust
912
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,242 advisories
Filter by severity
AMI SPx contains a vulnerability in the BMC where a User may cause a improper control of...
High
Unreviewed
CVE-2023-34330
was published
Jul 18, 2023
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present....
Critical
Unreviewed
CVE-2023-49070
was published
Dec 5, 2023
The CloudStack integration API service allows running its unauthenticated API server (usually on...
Critical
Unreviewed
CVE-2024-39864
was published
Jul 5, 2024
Apache NiFi vulnerable to Code Injection
High
CVE-2023-34468
was published
for
org.apache.nifi:nifi-dbcp-base
(Maven)
Jun 12, 2023
Apache Hive Code Injection vulnerability
Moderate
CVE-2023-35701
was published
for
org.apache.hive:hive-jdbc
(Maven)
May 3, 2024
RocketMQ NameServer component Code Injection vulnerability
Critical
CVE-2023-37582
was published
for
org.apache.rocketmq:rocketmq-namesrv
(Maven)
Jul 12, 2023
Apache NiFi Code Injection vulnerability
High
CVE-2023-36542
was published
for
org.apache.nifi:nifi-cdc-mysql-bundle
(Maven)
Jul 29, 2023
Apache Ambari: authenticated users could perform command injection to perform RCE
High
CVE-2023-50379
was published
for
org.apache.ambari.contrib.views:ambari-contrib-views
(Maven)
Feb 27, 2024
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
High
CVE-2023-5044
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Apache InLong Manager Remote Code Execution vulnerability
Critical
CVE-2023-51784
was published
for
org.apache.inlong:manager-pojo
(Maven)
Jan 3, 2024
Apache StreamPark: FreeMarker SSTI RCE Vulnerability
High
CVE-2024-29178
was published
for
org.apache.streampark:streampark
(Maven)
Jul 18, 2024
File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary...
High
Unreviewed
CVE-2021-3267
was published
Apr 4, 2023
Withdrawn Advisory: Command injection in Ray
Critical
CVE-2024-57000
was published
for
ray
(pip)
Feb 12, 2025
•
withdrawn
The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13797
was published
Feb 18, 2025
The Uncode Core plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
Moderate
Unreviewed
CVE-2024-13689
was published
Feb 18, 2025
JSONPath Plus allows Remote Code Execution
High
CVE-2025-1302
was published
for
jsonpath-plus
(npm)
Feb 15, 2025
Improper Control of Generation of Code ('Code Injection') in jai-ext
Critical
CVE-2022-24816
was published
for
it.geosolutions.jaiext.jiffle:jt-jiffle
(Maven)
Sep 19, 2023
Insufficient tracking and releasing of allocated used memory in libx264 git master allows...
Critical
Unreviewed
CVE-2025-25467
was published
Feb 19, 2025
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft...
Critical
Unreviewed
CVE-2023-25261
was published
Mar 27, 2023
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13792
was published
Feb 20, 2025
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary...
High
Unreviewed
CVE-2025-25943
was published
Feb 20, 2025
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary...
High
Unreviewed
CVE-2025-25944
was published
Feb 20, 2025
IBM Security Verify Access Appliance 10.0.0.0 through 10.0.0.9 and 11.0.0.0 could allow a local...
High
Unreviewed
CVE-2025-0161
was published
Feb 20, 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote...
Moderate
Unreviewed
CVE-2025-27218
was published
Feb 20, 2025
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to...
High
Unreviewed
CVE-2022-36386
was published
Sep 22, 2022
ProTip!
Advisories are also available from the
GraphQL API