GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
92,912 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Essential Marketer Essential Breadcrumbs...
High
Unreviewed
CVE-2024-53778
was published
Dec 1, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-53783
was published
Nov 30, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53739
was published
Nov 30, 2024
Qualys discovered that needrestart, before version 3.8, allows local attackers to execute...
High
Unreviewed
CVE-2024-48991
was published
Nov 19, 2024
xfpt versions prior to 1.01 fails to handle appropriately some parameters inside the input data,...
High
Unreviewed
CVE-2024-43700
was published
Aug 29, 2024
In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a...
High
Unreviewed
CVE-2017-13316
was published
Nov 27, 2024
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0...
High
Unreviewed
CVE-2024-52769
was published
Nov 20, 2024
An issue in Clementine v.1.3.1 allows a local attacker to execute arbitrary code via a crafted...
High
Unreviewed
CVE-2024-50986
was published
Nov 15, 2024
In installPackageLI of PackageManagerService.java, there is a possible permissions bypass. This...
High
Unreviewed
CVE-2018-9374
was published
Nov 28, 2024
In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow....
High
Unreviewed
CVE-2017-13323
was published
Nov 28, 2024
In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread...
High
Unreviewed
CVE-2017-13319
was published
Nov 27, 2024
EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS...
High
Unreviewed
CVE-2024-31976
was published
Nov 27, 2024
There are multiple stack-based buffer overflow vulnerabilities in V-SFT (v6.2.2.0 and earlier),...
High
Unreviewed
CVE-2024-38309
was published
Nov 28, 2024
In Click Studios Passwordstate before build 9920, there is a potential permission escalation on...
High
Unreviewed
CVE-2024-54124
was published
Nov 29, 2024
There is an Out-of-bounds read vulnerability in TELLUS (v4.0.19.0 and earlier) and TELLUS Lite ...
High
Unreviewed
CVE-2024-38389
was published
Nov 28, 2024
There is an Out-of-bounds read vulnerability in V-Server (v4.0.19.0 and earlier) and V-Server...
High
Unreviewed
CVE-2024-38658
was published
Nov 28, 2024
In the Linux kernel, the following vulnerability has been resolved:
fbdev: sisfb: Fix strbuf...
High
Unreviewed
CVE-2024-50180
was published
Nov 8, 2024
In the Linux kernel, the following vulnerability has been resolved:
x86/entry_32: Clear CPU...
High
Unreviewed
CVE-2024-50193
was published
Nov 8, 2024
IrfanView SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-11509
was published
Nov 22, 2024
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
could allow a locally authenticated...
High
Unreviewed
CVE-2024-49804
was published
Nov 29, 2024
there is a possible way to bypass due to a logic error in the code. This could lead to local...
High
Unreviewed
CVE-2024-29748
was published
Apr 5, 2024
Input verification vulnerability in the log module.
Impact: Successful exploitation of this...
High
Unreviewed
CVE-2024-27896
was published
Apr 8, 2024
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access...
High
Unreviewed
CVE-2024-48651
was published
Nov 29, 2024
By flooding the target resolver with queries exploiting this flaw an attacker can significantly...
High
Unreviewed
CVE-2022-2795
was published
Sep 22, 2022
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API....
High
Unreviewed
CVE-2024-11481
was published
Nov 29, 2024
ProTip!
Advisories are also available from the
GraphQL API