GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
242 advisories
Filter by severity
A vulnerability was found in SourceCodester Best POS Management System 1.0 and classified as...
Moderate
Unreviewed
CVE-2024-2155
was published
Mar 4, 2024
A vulnerability, which was classified as critical, has been found in SourceCodester Insurance...
Moderate
Unreviewed
CVE-2024-2150
was published
Mar 3, 2024
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
Critical
GHSA-97m3-52wr-xvv2
was published
for
phenx/php-svg-lib
(Composer)
Feb 22, 2024
A vulnerability, which was classified as critical, was found in SourceCodester Inventory...
Moderate
Unreviewed
CVE-2023-4749
was published
Sep 4, 2023
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an...
Moderate
Unreviewed
CVE-2023-0003
was published
Feb 8, 2023
A vulnerability classified as problematic was found in ForU CMS up to 2020-06-23. Affected by...
Moderate
Unreviewed
CVE-2024-0728
was published
Jan 19, 2024
A vulnerability in the file download feature of Cisco Firepower Management Center (FMC) Software...
Moderate
Unreviewed
CVE-2023-20114
was published
Nov 1, 2023
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to...
Moderate
Unreviewed
CVE-2023-20234
was published
Aug 23, 2023
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2024-0265
was published
Jan 7, 2024
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been...
Moderate
Unreviewed
CVE-2023-6618
was published
Dec 8, 2023
External Control of File Name or Path in h2oai/h2o-3
Critical
CVE-2023-6569
was published
for
h2o
(pip)
Dec 14, 2023
This external control vulnerability, if exploited, could allow a local OS-authenticated user...
Moderate
Unreviewed
CVE-2023-34982
was published
Nov 15, 2023
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple...
High
Unreviewed
CVE-2023-5247
was published
Nov 30, 2023
A vulnerability, which was classified as critical, has been found in SourceCodester Resort...
Moderate
Unreviewed
CVE-2023-4191
was published
Aug 7, 2023
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0...
Moderate
Unreviewed
CVE-2023-2152
was published
Apr 18, 2023
External Control of File Name or Path in GitHub repository unilogies/bumsys prior to 2.2.0.
High
Unreviewed
CVE-2023-2554
was published
May 5, 2023
A vulnerability was found in Boss Mini 1.4.0 Build 6221. It has been classified as critical. This...
High
Unreviewed
CVE-2023-3643
was published
Jul 12, 2023
Cortex's Alertmanager can expose local files content via specially crafted config
Moderate
CVE-2022-23536
was published
for
github.com/cortexproject/cortex
(Go)
Dec 19, 2022
ingress-nginx component for Kubernetes allows file overwrite
Moderate
CVE-2020-8553
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2022
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2022-2943
was published
Sep 7, 2022
Users of the LearnPress WordPress plugin before 4.1.5 can upload an image as a profile avatar...
Moderate
Unreviewed
CVE-2022-0377
was published
Mar 1, 2022
Dompdf before v2.0.0 vulnerable to chroot check bypass
Moderate
CVE-2022-2400
was published
for
dompdf/dompdf
(Composer)
Jul 19, 2022
This vulnerability allows network-adjacent attackers to disclose sensitive information on...
Moderate
Unreviewed
CVE-2021-27250
was published
May 24, 2022
Yapscan's report receiver server vulnerable to path traversal and log injection
High
GHSA-9h6h-9g78-86f7
was published
for
github.com/fkie-cad/yapscan
(Go)
Dec 29, 2022
The Plus Addons for Elementor plugin for WordPress is vulnerable to arbitrary file reads in...
Moderate
Unreviewed
CVE-2021-4332
was published
Mar 7, 2023
ProTip!
Advisories are also available from the
GraphQL API