GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
15 advisories
Filter by severity
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.4 prior to 17.5.1...
Moderate
Unreviewed
CVE-2025-0194
was published
Jan 8, 2025
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in...
Moderate
Unreviewed
CVE-2025-22306
was published
Jan 7, 2025
An attacker authenticated as an administrator can use an exposed webservice to upload or download...
Moderate
Unreviewed
CVE-2024-47579
was published
Dec 10, 2024
An attacker authenticated as an administrator can use an exposed webservice to create a PDF with...
Moderate
Unreviewed
CVE-2024-47580
was published
Dec 10, 2024
A vulnerability was found in 3Scale. There is no auth mechanism to see a PDF invoice of a...
Moderate
Unreviewed
CVE-2024-9671
was published
Oct 9, 2024
On Windows systems, the Arc configuration files resulted to be world-readable.
This can lead...
Moderate
Unreviewed
CVE-2023-5937
was published
May 15, 2024
A vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All...
Moderate
Unreviewed
CVE-2023-38558
was published
Sep 14, 2023
Due to an out-of-date dependency in the “Fusion File Manager” component accessible through the...
Moderate
Unreviewed
CVE-2023-4480
was published
Sep 5, 2023
A vulnerability in the web server functionality of Cisco Enterprise Network Functions...
Moderate
Unreviewed
CVE-2019-12623
was published
May 24, 2022
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
Moderate
Unreviewed
CVE-2018-20932
was published
May 24, 2022
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the...
Moderate
Unreviewed
CVE-2023-4933
was published
Oct 16, 2023
A vulnerability was found in RRJ Nueva Ecija Engineer Online Portal 1.0. It has been classified...
Moderate
Unreviewed
CVE-2024-0191
was published
Jan 2, 2024
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation...
Moderate
Unreviewed
CVE-2017-9947
was published
May 13, 2022
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR)...
Moderate
Unreviewed
CVE-2018-16970
was published
May 14, 2022
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified...
Moderate
Unreviewed
CVE-2021-1406
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API