GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,681
Pub
12
RubyGems
916
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
120 advisories
Filter by severity
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated,...
High
Unreviewed
CVE-2025-20236
was published
Apr 16, 2025
In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-33026
was published
Apr 15, 2025
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This...
Moderate
Unreviewed
CVE-2025-33027
was published
Apr 15, 2025
A flaw was found in Yelp. The Gnome user help application allows the help document to execute...
Moderate
Unreviewed
CVE-2025-3155
was published
Apr 3, 2025
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B...
High
Unreviewed
CVE-2024-45482
was published
Mar 25, 2025
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
Critical
Unreviewed
CVE-2025-27668
was published
Mar 5, 2025
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin...
High
Unreviewed
CVE-2024-13353
was published
Feb 21, 2025
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an...
Critical
Unreviewed
CVE-2025-0982
was published
Feb 6, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53800
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-56216
was published
Dec 31, 2024
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and...
High
Unreviewed
CVE-2024-54663
was published
Dec 20, 2024
The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does...
High
Unreviewed
CVE-2024-48336
was published
Nov 4, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-50497
was published
Oct 28, 2024
ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an...
Critical
Unreviewed
CVE-2024-9537
was published
Oct 18, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49243
was published
Oct 18, 2024
Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component...
High
Unreviewed
CVE-2022-49038
was published
Sep 26, 2024
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init...
High
Unreviewed
CVE-2024-45416
was published
Sep 16, 2024
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server...
High
Unreviewed
CVE-2024-43690
was published
Sep 11, 2024
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2024-8252
was published
Aug 30, 2024
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5762
was published
Aug 21, 2024
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel,...
Moderate
Unreviewed
CVE-2024-4359
was published
Aug 12, 2024
Anki Latex Incomplete Blocklist Vulnerability
Moderate
CVE-2024-29073
was published
for
anki
(pip)
Jul 22, 2024
Inclusion of Untrusted polyfill.io Code Vulnerability in fides.js
Low
CVE-2024-38537
was published
for
ethyca-fides
(pip)
Jul 2, 2024
ProTip!
Advisories are also available from the
GraphQL API