GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,051 advisories
Filter by severity
A vulnerability in the PPP over Ethernet (PPPoE) termination feature of Cisco IOS XR Software for...
High
Unreviewed
CVE-2024-20327
was published
Mar 13, 2024
A vulnerability in the Layer 2 Ethernet services of Cisco IOS XR Software could allow an...
High
Unreviewed
CVE-2024-20318
was published
Mar 13, 2024
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication...
High
Unreviewed
CVE-2024-0161
was published
Mar 13, 2024
Apache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS Proxying
High
CVE-2024-27894
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Mar 12, 2024
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
High
CVE-2024-27135
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Mar 12, 2024
Windows Kernel Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26173
was published
Mar 12, 2024
Windows Composite Image File System (CimFS) Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-26170
was published
Mar 12, 2024
Remote Code Execution Vulnerability in Microsoft Django Backend for SQL Server
High
CVE-2024-26164
was published
for
mssql-django
(pip)
Mar 12, 2024
ASA-2024-006: ValidateVoteExtensions helper function in Cosmos SDK may allow incorrect voting power assumptions
High
GHSA-95rx-m9m5-m94v
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Mar 12, 2024
An unauthenticated remote attacker can write memory out of bounds due to improper input...
High
Unreviewed
CVE-2024-26001
was published
Mar 12, 2024
An unauthenticated remote attacker can perform a command injection in the OCPP Service with...
High
Unreviewed
CVE-2024-25998
was published
Mar 12, 2024
An improper input validation in the Qualcom plctool allows a local attacker with low privileges...
High
Unreviewed
CVE-2024-26002
was published
Mar 12, 2024
An unauthenticated local attacker can perform a privilege escalation due to improper input...
High
Unreviewed
CVE-2024-25999
was published
Mar 12, 2024
In smp_proc_sec_req of smp_act.cc, there is a possible out of bounds read due to improper input...
High
Unreviewed
CVE-2024-0045
was published
Mar 11, 2024
PostgreSQL Anonymizer v1.2 contains a vulnerability that allows a user who owns a table to...
High
Unreviewed
CVE-2024-2339
was published
Mar 8, 2024
Numbas editor before 7.3 mishandles reading of themes and extensions.
High
Unreviewed
CVE-2024-27613
was published
Mar 8, 2024
A logic issue was addressed with improved validation. This issue is fixed in tvOS 17.4, macOS...
High
Unreviewed
CVE-2024-23263
was published
Mar 8, 2024
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14...
High
Unreviewed
CVE-2024-23294
was published
Mar 8, 2024
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14...
High
Unreviewed
CVE-2024-23246
was published
Mar 8, 2024
JFrog Artifactory prior to version 7.76.2 is vulnerable to Arbitrary File Write of untrusted data...
High
Unreviewed
CVE-2023-42661
was published
Mar 7, 2024
Coder's OIDC authentication allows email with partially matching domain to register
High
CVE-2024-27918
was published
for
github.com/coder/coder
(Go)
Mar 4, 2024
Transient DOS while processing CAG info IE received from NW.
High
Unreviewed
CVE-2023-33103
was published
Mar 4, 2024
Transient DOS while processing PDU Release command with a parameter PDU ID out of range.
High
Unreviewed
CVE-2023-33104
was published
Mar 4, 2024
In battery, there is a possible escalation of privilege due to a missing bounds check. This could...
High
Unreviewed
CVE-2024-20034
was published
Mar 4, 2024
IBM MQ and IBM MQ Appliance 9.0, 9.1, 9.2, 9.3 LTS and 9.3 CD could allow a remote...
High
Unreviewed
CVE-2024-25016
was published
Mar 3, 2024
ProTip!
Advisories are also available from the
GraphQL API