GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
336 advisories
Filter by severity
An issue in flusity CMS v2.33 allows a remote attacker to execute arbitrary code via the...
Critical
Unreviewed
CVE-2024-32418
was published
Apr 22, 2024
AWS Amplify CLI has incorrect trust policy management
Critical
CVE-2024-28056
was published
for
@aws-amplify/cli
(npm)
Apr 15, 2024
SQL Injection vulnerability in Tongtianxing Technology Co., Ltd CMSV6 v.7.31.0.2 through v.7.31.0...
Critical
Unreviewed
CVE-2024-29667
was published
Mar 29, 2024
An authentication bypass vulnerability was found in Stilog Visual Planning 8. It allows an...
Critical
Unreviewed
CVE-2023-49232
was published
Mar 29, 2024
An issue was discovered in tramyardg autoexpress version 1.3.0, allows unauthenticated remote...
Critical
Unreviewed
CVE-2023-48902
was published
Mar 21, 2024
SQL injection vulnerability in FME Modules quickproducttable module for PrestaShop v.1.2.1 and...
Critical
Unreviewed
CVE-2024-28391
was published
Mar 14, 2024
Android kernel allows Elevation of privilege.
Critical
Unreviewed
CVE-2024-27207
was published
Mar 11, 2024
In Blue Planet® products through 22.12, a misconfiguration in the SAML implementation allows...
Critical
Unreviewed
CVE-2024-2005
was published
Mar 6, 2024
An issue in Multilaser RE160V firmware v12.03.01.09_pt and Multilaser RE163V firmware v12.03.01...
Critical
Unreviewed
CVE-2023-38944
was published
Mar 6, 2024
SQL Injection vulnerability in MyPrestaModules "Product Catalog (CSV, Excel) Import" ...
Critical
Unreviewed
CVE-2024-25847
was published
Mar 3, 2024
An issue in Nagios XI 2024R1.01 allows a remote attacker to escalate privileges via a crafted...
Critical
Unreviewed
CVE-2024-24402
was published
Feb 26, 2024
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain...
Critical
Unreviewed
CVE-2023-47132
was published
Feb 9, 2024
HashiCorp Vault Improper Privilege Management
Critical
CVE-2020-10661
was published
for
github.com/hashicorp/vault
(Go)
Jan 30, 2024
An issue in Projectworlds Vistor Management Systemin PHP v.1.0 allows a remtoe attacker to...
Critical
Unreviewed
CVE-2024-22922
was published
Jan 26, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
Critical
CVE-2023-7080
was published
for
wrangler
(npm)
Jan 3, 2024
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user...
Critical
Unreviewed
CVE-2023-50921
was published
Jan 3, 2024
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access...
Critical
Unreviewed
CVE-2023-48418
was published
Jan 3, 2024
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in...
Critical
Unreviewed
CVE-2023-48419
was published
Jan 2, 2024
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard...
Critical
Unreviewed
CVE-2023-47267
was published
Dec 20, 2023
Improper Privilege Management in sap-xssec
Critical
CVE-2023-50423
was published
for
sap-xssec
(pip)
Dec 13, 2023
Improper Privilege Management in github.com/sap/cloud-security-client-go
Critical
CVE-2023-50424
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 13, 2023
Improper JWT Signature Validation in SAP Security Services Library
Critical
CVE-2023-50422
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 13, 2023
Duplicate Advisory: Privilege escalation in sap-xssec
Critical
GHSA-p99h-pfg6-qrfg
was published
for
sap-xssec
(pip)
Dec 12, 2023
•
withdrawn
Escalation of privileges in @sap/xssec
Critical
CVE-2023-49583
was published
for
@sap/xssec
(npm)
Dec 12, 2023
Duplicate Advisory: Privilege escalation in sap/cloud-security-client-go
Critical
GHSA-92cg-ghq6-9587
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 12, 2023
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API