GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
27,761 advisories
Filter by severity
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow...
Critical
Unreviewed
CVE-2023-30370
was published
Apr 24, 2023
In Tenda AC15 V15.03.05.19, the function "sub_ED14" contains a stack-based buffer overflow...
Critical
Unreviewed
CVE-2023-30371
was published
Apr 24, 2023
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow...
Critical
Unreviewed
CVE-2023-30372
was published
Apr 24, 2023
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow...
Critical
Unreviewed
CVE-2023-30373
was published
Apr 24, 2023
Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function.
Critical
Unreviewed
CVE-2023-30368
was published
Apr 24, 2023
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow.
Critical
Unreviewed
CVE-2023-30369
was published
Apr 24, 2023
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing
Critical
Unreviewed
CVE-2022-48477
was published
Apr 24, 2023
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and...
Critical
Unreviewed
CVE-2023-25131
was published
Apr 24, 2023
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel...
Critical
Unreviewed
CVE-2023-25132
was published
Apr 24, 2023
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local...
Critical
Unreviewed
CVE-2023-25133
was published
Apr 24, 2023
Expo SDK has an OAuth vulnerability
Critical
CVE-2023-28131
was published
for
expo
(npm)
Apr 24, 2023
Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE...
Critical
Unreviewed
CVE-2023-31060
was published
Apr 24, 2023
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as...
Critical
Unreviewed
CVE-2023-23753
was published
Apr 23, 2023
PowerJob vulnerable to incorrect access control
Critical
CVE-2023-29924
was published
for
tech.powerjob:powerjob
(Maven)
Apr 21, 2023
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar multiplication
Critical
CVE-2023-26556
was published
for
github.com/binance-chain/tss-lib
(Go)
Apr 21, 2023
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4...
Critical
Unreviewed
CVE-2023-2231
was published
Apr 21, 2023
Improper Authorization in modoboa
Critical
CVE-2023-2227
was published
for
modoboa
(pip)
Apr 21, 2023
XWiki Platform vulnerable to privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration
Critical
CVE-2023-29525
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to code injection from account through AWM view sheet
Critical
CVE-2023-29527
was published
for
org.xwiki.platform:xwiki-platform-appwithinminutes-ui
(Maven)
Apr 20, 2023
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
Critical
CVE-2023-29526
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to code injection from account through XWiki.SchedulerJobSheet
Critical
CVE-2023-29524
was published
for
org.xwiki.platform:xwiki-platform-scheduler-ui
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to code injection in display method used in user profiles
Critical
CVE-2023-29523
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector
Critical
CVE-2023-29516
was published
for
org.xwiki.platform:xwiki-platform-attachment-ui
(Maven)
Apr 20, 2023
XWiki vulnerable to Code Injection in template provider administration
Critical
CVE-2023-29514
was published
for
org.xwiki.platform.applications:xwiki-application-administration
(Maven)
Apr 20, 2023
xwiki-platform-web-templates vulnerable to Eval Injection
Critical
CVE-2023-29512
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 20, 2023
ProTip!
Advisories are also available from the
GraphQL API