GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
124 advisories
Filter by severity
A host header injection vulnerability exists in the forgot password functionality of ArrowCMS...
Critical
Unreviewed
CVE-2024-42914
was published
Aug 23, 2024
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000...
Critical
Unreviewed
CVE-2024-39227
was published
Aug 6, 2024
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR)...
Critical
Unreviewed
CVE-2024-40324
was published
Jul 25, 2024
Soft Circle French-Bread Melty Blood: Actress Again: Current Code through 1.07 Rev. 1.4.0 allows...
Critical
Unreviewed
CVE-2024-39704
was published
Jul 3, 2024
DataGear v5.0.0 and earlier was discovered to contain a SpEL (Spring Expression Language)...
Critical
Unreviewed
CVE-2024-37759
was published
Jun 24, 2024
An arbitrary file upload vulnerability in the component \modstudent\controller.php of Pisay...
Critical
Unreviewed
CVE-2024-34919
was published
May 17, 2024
Summary of Vulnerability
A template injection vulnerability on older versions of Confluence Data...
Critical
Unreviewed
CVE-2023-22527
was published
Jan 16, 2024
Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized...
Critical
Unreviewed
CVE-2024-0552
was published
Jan 15, 2024
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell...
Critical
Unreviewed
CVE-2023-46456
was published
Dec 12, 2023
This Template Injection vulnerability allows an authenticated attacker, including one with...
Critical
Unreviewed
CVE-2023-22522
was published
Dec 6, 2023
Usedesk before 1.7.57 allows chat template injection.
Critical
Unreviewed
CVE-2023-49214
was published
Nov 24, 2023
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user...
Critical
Unreviewed
CVE-2023-5340
was published
Nov 20, 2023
A vulnerability has been identified in SCALANCE XB205-3 (SC, PN) (All versions < V4.5), SCALANCE...
Critical
Unreviewed
CVE-2023-44373
was published
Nov 14, 2023
Terminal character injection in Mintty before 3.6.3 allows code execution via unescaped output to...
Critical
Unreviewed
CVE-2022-47583
was published
Oct 19, 2023
Using the TIOCLINUX ioctl request, a malicious snap could inject contents into the input of the...
Critical
Unreviewed
CVE-2023-1523
was published
Sep 1, 2023
TerraMaster NAS through 4.2.30 allows remote WAN attackers to execute arbitrary code as root via...
Critical
Unreviewed
CVE-2022-24989
was published
Aug 20, 2023
Crypto wallets implementing the GG18 or GG20 TSS protocol might allow an attacker to extract a...
Critical
Unreviewed
CVE-2023-33241
was published
Aug 10, 2023
Improper neutralization of special elements in Zoom Desktop Client for Windows and Zoom VDI...
Critical
Unreviewed
CVE-2023-39213
was published
Aug 9, 2023
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template...
Critical
Unreviewed
CVE-2023-36210
was published
Aug 1, 2023
An unauthorized node injection vulnerability has been identified in ROS2 Foxy Fitzroy versions...
Critical
Unreviewed
CVE-2023-33566
was published
Jun 27, 2023
The go command may execute arbitrary code at build time when using cgo. This may occur when...
Critical
Unreviewed
CVE-2023-29405
was published
Jun 8, 2023
Not all valid JavaScript whitespace characters are considered to be whitespace. Templates...
Critical
Unreviewed
CVE-2023-24540
was published
May 11, 2023
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable,...
Critical
Unreviewed
CVE-2023-29827
was published
May 4, 2023
Simple Image Gallery v1.0 was discovered to contain a remote code execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2023-27040
was published
Mar 16, 2023
In UBIKA WAAP Gateway/Cloud through 6.10, a blind XPath injection leads to an authentication...
Critical
Unreviewed
CVE-2023-26261
was published
Mar 8, 2023
ProTip!
Advisories are also available from the
GraphQL API