GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
2,343 advisories
Filter by severity
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and...
High
Unreviewed
CVE-2024-40442
was published
Sep 23, 2024
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology...
High
Unreviewed
CVE-2024-40125
was published
Sep 19, 2024
sqlitedict insecure deserialization vulnerability
High
CVE-2024-35515
was published
for
sqlitedict
(pip)
Sep 18, 2024
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code...
High
Unreviewed
CVE-2024-44623
was published
Sep 16, 2024
The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in...
High
Unreviewed
CVE-2024-8479
was published
Sep 16, 2024
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-8271
was published
Sep 16, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45851
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45846
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45848
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45847
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45849
was published
for
mindsdb
(pip)
Sep 12, 2024
MindsDB Eval Injection vulnerability
High
CVE-2024-45850
was published
for
mindsdb
(pip)
Sep 12, 2024
Azure CycleCloud Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43469
was published
Sep 10, 2024
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-8478
was published
Sep 10, 2024
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to...
High
Unreviewed
CVE-2024-8268
was published
Sep 10, 2024
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url...
High
Unreviewed
CVE-2024-44724
was published
Sep 9, 2024
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC...
High
Unreviewed
CVE-2024-38651
was published
Sep 7, 2024
A code injection vulnerability that allows a low-privileged user with REST API access granted to...
High
Unreviewed
CVE-2024-39715
was published
Sep 7, 2024
The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0...
High
Unreviewed
CVE-2024-7627
was published
Sep 5, 2024
Remote Code Execution Vulnerability via SSTI in Fides Webserver Jinja Email Templating Engine
High
CVE-2024-45053
was published
for
ethyca-fides
(pip)
Sep 4, 2024
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to...
High
Unreviewed
CVE-2024-42902
was published
Sep 3, 2024
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit...
High
Unreviewed
CVE-2024-7345
was published
Sep 3, 2024
UltiMaker Cura slicer versions 5.7.0-beta.1 through 5.7.2 are vulnerable to code injection via...
High
Unreviewed
CVE-2024-8374
was published
Sep 3, 2024
A code execution vulnerability exists in the XiaomiGetApps application product. This...
High
Unreviewed
CVE-2023-26322
was published
Aug 28, 2024
A code execution vulnerability exists in the XiaomiGetApps application product. This...
High
Unreviewed
CVE-2023-26324
was published
Aug 28, 2024
ProTip!
Advisories are also available from the
GraphQL API