GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
4,023 advisories
Filter by severity
Reportlab vulnerable to remote code execution
High
CVE-2023-33733
was published
for
reportlab
(pip)
Jun 5, 2023
An authenticated arbitrary file upload vulnerability in the component /module_admin/upload.php of...
High
Unreviewed
CVE-2024-53564
was published
Dec 2, 2024
File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50660
was published
Jan 7, 2025
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to...
Critical
Unreviewed
CVE-2024-50658
was published
Jan 7, 2025
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote...
Moderate
Unreviewed
CVE-2024-25706
was published
Apr 4, 2024
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all...
Critical
Unreviewed
CVE-2024-11635
was published
Jan 8, 2025
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution, Arbitrary...
Critical
Unreviewed
CVE-2024-11613
was published
Jan 8, 2025
Vulnerability of improper access control in the home screen widget module
Impact: Successful...
Moderate
Unreviewed
CVE-2024-56448
was published
Jan 8, 2025
A vulnerability was found in code-projects Online Book Shop 1.0 and classified as problematic....
Moderate
Unreviewed
CVE-2025-0295
was published
Jan 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP...
Critical
Unreviewed
CVE-2024-56278
was published
Jan 7, 2025
The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator...
High
Unreviewed
CVE-2024-12471
was published
Jan 7, 2025
The The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12419
was published
Jan 7, 2025
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing...
Critical
Unreviewed
CVE-2024-12252
was published
Jan 7, 2025
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
Critical
Unreviewed
CVE-2024-55529
was published
Jan 6, 2025
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29404
was published
Jun 8, 2023
A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file...
Moderate
Unreviewed
CVE-2023-6601
was published
Jan 6, 2025
A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage...
Moderate
Unreviewed
CVE-2023-6604
was published
Jan 6, 2025
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1...
Critical
Unreviewed
CVE-2023-35034
was published
Jun 12, 2023
A potential security vulnerability has been identified with a version of the HP Softpaq installer...
High
Unreviewed
CVE-2019-16283
was published
Jun 9, 2023
D-Link DIR-806 devices allow remote attackers to execute arbitrary shell commands via a trailing...
Critical
Unreviewed
CVE-2019-10891
was published
May 24, 2022
The The WordPress Popular Posts plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-11733
was published
Jan 4, 2025
Server Side Template Injection (SSTI) via Twig escape handler
High
CVE-2024-28119
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
Server Side Template Injection (SSTI)
High
CVE-2024-28118
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
Server Side Template Injection (SSTI)
High
CVE-2024-28117
was published
for
getgrav/grav
(Composer)
Mar 22, 2024
.NET Remote Code Execution Vulnerability
High
CVE-2022-41089
was published
for
Microsoft.WindowsDesktop.App.Runtime.win-arm64
(NuGet)
Dec 14, 2022
ProTip!
Advisories are also available from the
GraphQL API