GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,765 advisories
Filter by severity
@pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution
Critical
CVE-2022-25644
was published
for
@pendo324/get-process-by-name
(npm)
Aug 29, 2022
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with...
Critical
Unreviewed
CVE-2021-20623
was published
May 24, 2022
Improper Control of Generation of Code in doT
High
CVE-2020-8141
was published
for
dot
(npm)
May 24, 2022
Improper Control of Generation of Code in Apache Kafka
Moderate
CVE-2018-1288
was published
for
org.apache.kafka:kafka
(Maven)
May 13, 2022
Improper Control of Generation of Code in Spring Security
Moderate
CVE-2011-2732
was published
for
org.springframework.security:spring-security-core
(Maven)
May 17, 2022
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to...
High
Unreviewed
CVE-2022-3383
was published
Nov 29, 2022
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to...
High
Unreviewed
CVE-2022-3384
was published
Nov 29, 2022
morgan-json vulnerable to Arbitrary Code Execution
Critical
CVE-2022-25921
was published
for
morgan-json
(npm)
Aug 29, 2022
PHPMailer susceptible to arbitrary code execution
High
CVE-2008-5619
was published
for
phpmailer/phpmailer
(Composer)
May 14, 2022
PaddlePaddle vulnerable to code injection via winstr
Critical
CVE-2022-45908
was published
for
paddlepaddle
(pip)
Nov 26, 2022
A vulnerability was reported in Lenovo System Update that could allow a local user with...
High
Unreviewed
CVE-2022-0354
was published
Apr 23, 2022
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the...
High
Unreviewed
CVE-2022-0661
was published
Apr 19, 2022
There is a logic bypass vulnerability in smartphones. Successful exploitation of this...
Critical
Unreviewed
CVE-2021-22430
was published
Feb 26, 2022
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote...
High
Unreviewed
CVE-2010-3205
was published
May 17, 2022
PHP remote file inclusion vulnerability in core/include/myMailer.class.php in the Visites ...
High
Unreviewed
CVE-2010-2918
was published
May 17, 2022
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for...
Critical
Unreviewed
CVE-2020-15591
was published
Mar 18, 2022
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16...
High
Unreviewed
CVE-2021-45661
was published
Dec 27, 2021
A zero-code remote code injection vulnerability via configuration.php in Chamilo LMS v1.11.13...
High
Unreviewed
CVE-2022-27427
was published
Apr 16, 2022
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00...
High
Unreviewed
CVE-2021-45657
was published
Dec 27, 2021
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00...
High
Unreviewed
CVE-2021-45656
was published
Dec 27, 2021
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.
Moderate
Unreviewed
CVE-2021-45655
was published
Dec 27, 2021
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16...
High
Unreviewed
CVE-2021-45660
was published
Dec 27, 2021
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16...
High
Unreviewed
CVE-2021-45659
was published
Dec 27, 2021
ProTip!
Advisories are also available from the
GraphQL API