GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,286
Erlang
31
GitHub Actions
21
Go
2,058
Maven
5,000+
npm
3,742
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
11,273 advisories
Filter by severity
in OpenHarmony v3.2.4 and prior versions allow a local attacker cause apps crash through type...
Low
Unreviewed
CVE-2023-49602
was published
Mar 4, 2024
Concrete CMS Stored XSS
Low
CVE-2023-49337
was published
for
concrete5/concrete5
(Composer)
Feb 29, 2024
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
ChatBar.tsx in Lumos before 1.0.17 parses raw HTML in Markdown because the markdown-to-jsx...
Low
Unreviewed
CVE-2024-56082
was published
Dec 15, 2024
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Low
Unreviewed
CVE-2024-44290
was published
Dec 12, 2024
This issue was addressed with improved redaction of sensitive information. This issue is fixed in...
Low
Unreviewed
CVE-2024-44200
was published
Dec 12, 2024
The issue was addressed by adding additional logic. This issue is fixed in iPadOS 17.7.3, iOS 18...
Low
Unreviewed
CVE-2024-54485
was published
Dec 12, 2024
Mattermost Server Improper Access Control
Low
CVE-2024-21848
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Apr 5, 2024
Mattermost race condition
Low
CVE-2024-1949
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 29, 2024
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia...
Low
Unreviewed
CVE-2024-54493
was published
Dec 12, 2024
Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2023-41695
was published
Dec 13, 2024
Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly...
Low
Unreviewed
CVE-2022-45819
was published
Dec 13, 2024
Symfony has an incorrect response from Validator when input ends with `\n`
Low
CVE-2024-50343
was published
for
symfony/symfony
(Composer)
Nov 6, 2024
This issue affects:
Secomea GateManager
Version 9.5 and all prior versions.
Protection Mechanism...
Low
Unreviewed
CVE-2021-32007
was published
Dec 13, 2024
The AR for WordPress plugin for WordPress is vulnerable to unauthorized double extension file...
Low
Unreviewed
CVE-2024-12300
was published
Dec 13, 2024
Magento Open Source Improper Access Control vulnerability
Low
CVE-2024-45149
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
An issue has been discovered in GitLab EE affecting all versions starting from 14.3 before 17.4.6...
Low
Unreviewed
CVE-2024-10043
was published
Dec 12, 2024
Possible Content Security Policy bypass in Action Dispatch
Low
CVE-2024-54133
was published
for
actionpack
(RubyGems)
Dec 10, 2024
lxd CA certificate sign check bypass
Low
CVE-2024-6156
was published
for
github.com/canonical/lxd
(Go)
Dec 9, 2024
sigstore has insufficient validation of integration timestamp during verification
Low
CVE-2024-55655
was published
for
sigstore
(pip)
Dec 11, 2024
IBM InfoSphere DataStage Flow Designer (InfoSphere Information Server 11.7) could allow an...
Low
Unreviewed
CVE-2023-23472
was published
Dec 11, 2024
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain sensitive information...
Low
Unreviewed
CVE-2023-37395
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-52831
was published
Dec 11, 2024
Adobe Experience Manager versions 6.5.21 and earlier are affected by an Improper Input Validation...
Low
Unreviewed
CVE-2024-43755
was published
Dec 11, 2024
Adobe Connect versions 12.6, 11.4.7 and earlier are affected by a URL Redirection to Untrusted...
Low
Unreviewed
CVE-2024-54051
was published
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API