GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,054 advisories
Filter by severity
An issue discovered in GPAC 2.3-DEV-rev605-gfc9e29089-master in MP4Box in gf_avc_change_vui ...
High
Unreviewed
CVE-2023-46929
was published
Jan 3, 2024
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the...
High
Unreviewed
CVE-2023-49551
was published
Jan 3, 2024
Potential Actions command injection in output filenames (GHSL-2023-275)
High
CVE-2023-52137
was published
for
tj-actions/verify-changed-files
(GitHub Actions)
Jan 2, 2024
Information disclosure in Core services while processing a Diag command.
High
Unreviewed
CVE-2023-33014
was published
Jan 2, 2024
In modem EMM, there is a possible system crash due to improper input validation. This could lead...
High
Unreviewed
CVE-2023-32890
was published
Jan 2, 2024
Apache DolphinScheduler: Arbitrary js execute as root for authenticated users
High
CVE-2023-49299
was published
for
org.apache.dolphinscheduler:dolphinscheduler-master
(Maven)
Dec 30, 2023
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments....
High
Unreviewed
CVE-2023-47804
was published
Dec 29, 2023
Maliciously crafted Git server replies can cause DoS on go-git clients
High
CVE-2023-49568
was published
for
github.com/go-git/go-git/v5
(Go)
Dec 27, 2023
Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote...
High
Unreviewed
CVE-2023-31289
was published
Dec 25, 2023
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to...
High
Unreviewed
CVE-2023-31455
was published
Dec 25, 2023
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user...
High
Unreviewed
CVE-2023-39509
was published
Dec 22, 2023
An attacker who has the privilege to configure Zabbix items can use function icmpping() with...
High
Unreviewed
CVE-2023-32727
was published
Dec 22, 2023
The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restricted
High
CVE-2023-6291
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 21, 2023
A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system...
High
Unreviewed
CVE-2023-0011
was published
Dec 20, 2023
By abusing a design flaw in the firmware upgrade mechanism of the impacted terminal it's...
High
Unreviewed
CVE-2023-33217
was published
Dec 15, 2023
Adobe After Effects versions 24.0.3 (and earlier) and 23.6.0 (and earlier) are affected by an...
High
Unreviewed
CVE-2023-48634
was published
Dec 13, 2023
A vulnerability has been identified in Opcenter Quality (All versions), SIMATIC PCS neo (All...
High
Unreviewed
CVE-2023-46285
was published
Dec 12, 2023
Improper Input Validation in the processing of user-supplied splash screen during system boot in...
High
Unreviewed
CVE-2023-5058
was published
Dec 8, 2023
An issue was discovered in Dalmann OCPP.Core through 1.2.0 for OCPP (Open Charge Point Protocol)...
High
Unreviewed
CVE-2023-49958
was published
Dec 7, 2023
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a...
High
Unreviewed
CVE-2023-39539
was published
Dec 6, 2023
AMI AptioV contains a vulnerability in BIOS where a User may cause an unrestricted upload of a...
High
Unreviewed
CVE-2023-39538
was published
Dec 6, 2023
The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol...
High
Unreviewed
CVE-2023-5188
was published
Dec 5, 2023
Improper URL validation from InstantPlay deeplink in Galaxy Store prior to version 4.5.64.4...
High
Unreviewed
CVE-2023-42581
was published
Dec 5, 2023
Transient DOS in Modem after RRC Setup message is received.
High
Unreviewed
CVE-2023-33042
was published
Dec 5, 2023
In hasPermissionForActivity of PackageManagerHelper.java, there is a possible URI grant due to...
High
Unreviewed
CVE-2023-40097
was published
Dec 5, 2023
ProTip!
Advisories are also available from the
GraphQL API