GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
39 advisories
Filter by severity
A sshconfig expression language injection remote code execution vulnerability was discovered in...
High
Unreviewed
CVE-2020-7182
was published
May 24, 2022
A wmiconfigcontent expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7177
was published
May 24, 2022
A thirdpartyperfselecttask expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7179
was published
May 24, 2022
A actionselectcontent expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7173
was published
May 24, 2022
A mediaforaction expression language injection remote code execution vulnerability was discovered...
High
Unreviewed
CVE-2020-7178
was published
May 24, 2022
A soapconfigcontent expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7174
was published
May 24, 2022
A viewtaskresultdetailfact expression language injection remote code execution vulnerability was...
High
Unreviewed
CVE-2020-7176
was published
May 24, 2022
Apache MyFaces Vulnerable to EL Injection
High
CVE-2011-4343
was published
for
org.apache.myfaces.core:myfaces-core-module
(Maven)
May 17, 2022
Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.
High
Unreviewed
CVE-2018-16621
was published
May 13, 2022
An issue was discovered in ZZZCMS zzzphp V1.6.1. In the inc/zzz_template.php file, the...
High
Unreviewed
CVE-2019-9041
was published
May 13, 2022
Improper Input Validation in GeoServer
High
CVE-2022-24847
was published
for
org.geoserver:gs-main
(Maven)
Apr 22, 2022
Remote Code Execution in SCIMono
High
CVE-2021-21479
was published
for
com.sap.scimono:scimono-server
(Maven)
Feb 10, 2021
Remote Code Execution in SyliusResourceBundle
High
CVE-2020-15143
was published
for
sylius/resource-bundle
(Composer)
Aug 19, 2020
Nexus Repository Manager 3 - Remote Code Execution
High
CVE-2020-10199
was published
for
org.sonatype.nexus:nexus-extdirect
(Maven)
Apr 14, 2020
ProTip!
Advisories are also available from the
GraphQL API