GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,846
Erlang
36
GitHub Actions
33
Go
2,467
Maven
5,000+
npm
4,090
NuGet
733
pip
3,907
Pub
12
RubyGems
944
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,753 advisories
Filter by severity
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in...
Critical
Unreviewed
CVE-2022-32520
was published
Jan 31, 2023
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a...
Critical
Unreviewed
CVE-2022-32524
was published
Jan 31, 2023
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in...
Critical
Unreviewed
CVE-2022-32518
was published
Jan 31, 2023
An arbitrary file upload vulnerability in taocms v3.0.2 allows attackers to execute arbitrary...
Critical
Unreviewed
CVE-2022-48006
was published
Jan 31, 2023
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior could bypass the brute force protection...
Critical
Unreviewed
CVE-2023-24020
was published
Jan 31, 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause...
Critical
Unreviewed
CVE-2022-32528
was published
Jan 31, 2023
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the...
Critical
Unreviewed
CVE-2022-48175
was published
Jan 31, 2023
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a...
Critical
Unreviewed
CVE-2022-32529
was published
Jan 31, 2023
Snap One Wattbox WB-300-IP-3 versions WB10.9a17 and prior are vulnerable to a heap-based buffer...
Critical
Unreviewed
CVE-2023-23582
was published
Jan 31, 2023
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a...
Critical
Unreviewed
CVE-2022-32527
was published
Jan 31, 2023
The Membership For WooCommerce WordPress plugin before 2.1.7 does not validate uploaded files,...
Critical
Unreviewed
CVE-2022-4395
was published
Jan 30, 2023
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature...
Critical
Unreviewed
CVE-2022-23334
was published
Jan 30, 2023
An OS command injection vulnerability exists in the httpd logs/view.cgi functionality of...
Critical
Unreviewed
CVE-2022-42484
was published
Jan 30, 2023
A vulnerability has been reported to affect QNAP device running QuTS hero, QTS. If exploited,...
Critical
Unreviewed
CVE-2022-27596
was published
Jan 30, 2023
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an...
Critical
Unreviewed
CVE-2023-24612
was published
Jan 30, 2023
A vulnerability, which was classified as critical, was found in SourceCodester Online Tours &...
Critical
Unreviewed
CVE-2023-0570
was published
Jan 29, 2023
A vulnerability was found in PHPGurukul Bank Locker Management System 1.0. It has been rated as...
Critical
Unreviewed
CVE-2023-0562
was published
Jan 29, 2023
There is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is...
Critical
Unreviewed
CVE-2022-43979
was published
Jan 28, 2023
Italtel NetMatch-S CI 5.2.0-20211008 has incorrect Access Control under NMSCI-WebGui...
Critical
Unreviewed
CVE-2022-39811
was published
Jan 28, 2023
The ContentStudio plugin for WordPress is vulnerable to authorization bypass due to an unsecure...
Critical
Unreviewed
CVE-2023-0558
was published
Jan 28, 2023
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-48107
was published
Jan 27, 2023
D-Link DIR_878_FW1.30B08 was discovered to contain a command injection vulnerability via the...
Critical
Unreviewed
CVE-2022-48108
was published
Jan 27, 2023
Opencats v0.9.7 was discovered to contain a SQL injection vulnerability via the importID...
Critical
Unreviewed
CVE-2022-48011
was published
Jan 27, 2023
An arbitrary file upload vulnerability in the plugin manager of LimeSurvey v5.4.15 allows...
Critical
Unreviewed
CVE-2022-48008
was published
Jan 27, 2023
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
Critical
Unreviewed
CVE-2022-44298
was published
Jan 27, 2023
ProTip!
Advisories are also available from the
GraphQL API