GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
118 advisories
Filter by severity
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27943
was published
May 14, 2024
Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an external control of file name or...
Moderate
Unreviewed
CVE-2024-25965
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27944
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import...
High
Unreviewed
CVE-2024-27945
was published
May 14, 2024
A vulnerability was found in Campcodes Online Laundry Management System 1.0 and classified as...
Moderate
Unreviewed
CVE-2024-4818
was published
May 14, 2024
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user can set the...
Critical
Unreviewed
CVE-2024-0087
was published
May 14, 2024
NVIDIA Triton Inference Server for Linux contains a vulnerability in the tracing API, where a...
Moderate
Unreviewed
CVE-2024-0100
was published
May 14, 2024
An issue was discovered in Logpoint before 7.4.0. It allows Local File Inclusion (LFI) when an...
Moderate
Unreviewed
CVE-2024-33860
was published
May 7, 2024
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec...
High
Unreviewed
CVE-2024-33671
was published
Apr 26, 2024
timber/timber vulnerable to Deserialization of Untrusted Data
High
CVE-2024-29800
was published
for
timber/timber
(Composer)
Apr 12, 2024
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3...
High
Unreviewed
CVE-2024-31492
was published
Apr 10, 2024
A file write vulnerability exists in the OAS Engine Save Security Configuration functionality of...
Moderate
Unreviewed
CVE-2024-22178
was published
Apr 3, 2024
A file write vulnerability exists in the OAS Engine Tags Configuration functionality of Open...
Moderate
Unreviewed
CVE-2024-21870
was published
Apr 3, 2024
A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared...
Moderate
Unreviewed
CVE-2024-2917
was published
Mar 27, 2024
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
High
CVE-2024-1603
was published
for
paddlepaddle
(pip)
Mar 23, 2024
An issue in Advanced Plugins reportsstatistics v1.3.20 and before allows a remote attacker to...
Critical
Unreviewed
CVE-2024-28394
was published
Mar 20, 2024
GeoServer Arbitrary file renaming vulnerability in REST Coverage/Data Store API
Moderate
CVE-2024-23634
was published
for
org.geoserver:gs-restconfig
(Maven)
Mar 20, 2024
IBM Sterling Secure Proxy 6.0.3 and 6.1.0 could allow an attacker to overwrite a log message...
Moderate
Unreviewed
CVE-2023-47147
was published
Mar 15, 2024
Windows Compressed Folder Tampering Vulnerability
Moderate
Unreviewed
CVE-2024-26185
was published
Mar 12, 2024
IBM Watson CP4D Data Stores 4.6.0 through 4.6.3 could allow a user with physical access and...
Moderate
Unreviewed
CVE-2023-26282
was published
Mar 5, 2024
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as...
Moderate
Unreviewed
CVE-2024-2155
was published
Mar 4, 2024
A vulnerability, which was classified as critical, has been found in SourceCodester Insurance...
Moderate
Unreviewed
CVE-2024-2150
was published
Mar 3, 2024
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
Critical
GHSA-97m3-52wr-xvv2
was published
for
phenx/php-svg-lib
(Composer)
Feb 22, 2024
php-svg-lib lacks path validation on font through SVG inline styles
Moderate
CVE-2024-25117
was published
for
phenx/php-svg-lib
(Composer)
Feb 21, 2024
ProTip!
Advisories are also available from the
GraphQL API