GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,303
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
669
pip
3,430
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,333 advisories
Filter by severity
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2...
High
Unreviewed
CVE-2024-30964
was published
Dec 6, 2024
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2...
High
Unreviewed
CVE-2024-30961
was published
Dec 6, 2024
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via...
High
Unreviewed
CVE-2024-10952
was published
Dec 4, 2024
An authenticated arbitrary file upload vulnerability in the component /module_admin/upload.php of...
High
Unreviewed
CVE-2024-53564
was published
Dec 2, 2024
Withdrawn Advisory: Symfony's VarDumper vulnerable to unsafe deserialization
High
CVE-2024-36610
was published
for
symfony/var-dumper
(Composer)
Nov 29, 2024
•
withdrawn
Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows...
High
Unreviewed
CVE-2024-11620
was published
Nov 28, 2024
When handling keypress events, an attacker may have been able to trick a user into bypassing the ...
High
Unreviewed
CVE-2024-11697
was published
Nov 26, 2024
Memory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of...
High
Unreviewed
CVE-2024-11699
was published
Nov 26, 2024
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject...
High
Unreviewed
CVE-2024-52899
was published
Nov 26, 2024
A Client-Side Template Injection (CSTI) vulnerability in the component /project/new/scrum of...
High
Unreviewed
CVE-2024-53554
was published
Nov 26, 2024
The The Request a Quote for WooCommerce and Elementor – Get a Quote Button – Product Enquiry Form...
High
Unreviewed
CVE-2024-11034
was published
Nov 23, 2024
Possible Command injection Vulnerability
in iManager has been discovered in
OpenText™ iManager 3...
High
Unreviewed
CVE-2021-38117
was published
Nov 22, 2024
There exists a code execution vulnerability in the Car App Android Jetpack Library. In the...
High
Unreviewed
CVE-2024-10382
was published
Nov 20, 2024
The The WooCommerce Product Table Lite plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-10899
was published
Nov 20, 2024
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in...
High
Unreviewed
CVE-2024-11036
was published
Nov 19, 2024
The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7...
High
Unreviewed
CVE-2024-11038
was published
Nov 19, 2024
Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a...
High
Unreviewed
CVE-2024-50804
was published
Nov 18, 2024
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup...
High
Unreviewed
CVE-2024-52945
was published
Nov 18, 2024
The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
High
Unreviewed
CVE-2024-9839
was published
Nov 16, 2024
Remote Code Execution on click of <a> Link in markdown preview
High
CVE-2024-49362
was published
for
joplin
(npm)
Nov 14, 2024
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2.
This...
High
Unreviewed
CVE-2024-5082
was published
Nov 14, 2024
In DevmemIntChangeSparse2 of devicemem_server.c, there is a possible way to achieve arbitrary...
High
Unreviewed
CVE-2024-40671
was published
Nov 13, 2024
Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
High
CVE-2024-52293
was published
for
craftcms/cms
(Composer)
Nov 13, 2024
TorchGeo Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-49048
was published
Nov 12, 2024
Improper input validation in the NPU driver could allow an attacker to supply a specially crafted...
High
Unreviewed
CVE-2024-21976
was published
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API