GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,313
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
669
pip
3,433
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
Cachet configuration leak
High
CVE-2021-39174
was published
for
cachethq/cachet
(Composer)
Aug 30, 2021
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub...
High
Unreviewed
CVE-2023-0302
was published
Jan 15, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter
High
CVE-2023-1758
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET...
High
Unreviewed
CVE-2023-27533
was published
Mar 30, 2023
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions...
High
Unreviewed
CVE-2024-36997
was published
Jul 1, 2024
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions...
High
Unreviewed
CVE-2024-36983
was published
Jul 1, 2024
An injection issue was addressed with improved input validation. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-23268
was published
Mar 8, 2024
An injection issue was addressed with improved input validation. This issue is fixed in macOS...
High
Unreviewed
CVE-2024-23274
was published
Mar 8, 2024
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an...
High
Unreviewed
CVE-2024-24257
was published
Jul 26, 2024
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE)...
High
Unreviewed
CVE-2024-31809
was published
Apr 8, 2024
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform...
High
Unreviewed
CVE-2024-37570
was published
Jun 9, 2024
** DISPUTED ** The tf_remapper_node component 1.1.1 for Robot Operating System (ROS) allows...
High
Unreviewed
CVE-2022-48217
was published
Jan 4, 2023
Winter CMS Server-Side Template Injection (SSTI) vulnerability
High
CVE-2024-29686
was published
for
wintercms/winter
(Composer)
Mar 29, 2024
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS...
High
Unreviewed
CVE-2024-27622
was published
Mar 5, 2024
A denial of service vulnerability exists in Arcserve Unified Data Protection 9.2 and 8.1 in...
High
Unreviewed
CVE-2024-0801
was published
Mar 13, 2024
Untrusted Query Object Evaluation in RPC API
High
GHSA-64f8-pjgr-9wmr
was published
for
surrealdb
(Rust)
Sep 11, 2024
Special Element Injection in notebook
High
CVE-2021-32798
was published
for
notebook
(pip)
Aug 23, 2021
ProTip!
Advisories are also available from the
GraphQL API