GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
145 advisories
Filter by severity
The InstaWP Connect plugin for WordPress is vulnerable to unauthorized access of data,...
Critical
Unreviewed
CVE-2023-3956
was published
Jul 27, 2023
Certain HP LaserJet Pro print products are potentially vulnerable to an Elevation of Privilege...
Critical
Unreviewed
CVE-2023-26301
was published
Jul 21, 2023
The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user...
Critical
Unreviewed
CVE-2023-3076
was published
Jul 10, 2023
The Quiz And Survey Master for WordPress is vulnerable to authorization bypass due to a missing...
Critical
Unreviewed
CVE-2023-0291
was published
Jun 9, 2023
The uListing plugin for WordPress is vulnerable to authorization bypass via wp_route due to...
Critical
Unreviewed
CVE-2021-4381
was published
Jun 7, 2023
The uListing plugin for WordPress is vulnerable to authorization bypass as most actions and...
Critical
Unreviewed
CVE-2021-4370
was published
Jun 7, 2023
The WordPress Automatic Plugin for WordPress is vulnerable to arbitrary options updates in...
Critical
Unreviewed
CVE-2021-4374
was published
Jun 7, 2023
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File...
Critical
Unreviewed
CVE-2021-4356
was published
Jun 7, 2023
The Kiwi Social Share plugin for WordPress is vulnerable to authorization bypass due to a missing...
Critical
Unreviewed
CVE-2021-4362
was published
Jun 7, 2023
The Unauthenticated Account Creation plugin for WordPress is vulnerable to Unauthenticated...
Critical
Unreviewed
CVE-2021-4343
was published
Jun 7, 2023
The CMP for WordPress is vulnerable to authorization bypass due to a missing capability check on...
Critical
Unreviewed
CVE-2020-36730
was published
Jun 7, 2023
The uListing plugin for WordPress is vulnerable to authorization bypass via Ajax due to missing...
Critical
Unreviewed
CVE-2021-4341
was published
Jun 7, 2023
The Easy WP SMTP plugin for WordPress is vulnerable to authorization bypass in versions up to,...
Critical
Unreviewed
CVE-2019-25141
was published
Jun 7, 2023
The ListingPro - WordPress Directory & Listing Theme for WordPress is vulnerable to Arbitrary...
Critical
Unreviewed
CVE-2020-36719
was published
Jun 7, 2023
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app,...
Critical
Unreviewed
CVE-2023-2193
was published
Apr 20, 2023
THe WCFM Membership plugin for WordPress is vulnerable to privilege escalation in versions up to,...
Critical
Unreviewed
CVE-2022-4939
was published
Apr 5, 2023
SAP NetWeaver Application Server for ABAP and ABAP Platform - versions 700, 701, 702, 731, 740,...
Critical
Unreviewed
CVE-2023-27269
was published
Mar 14, 2023
The Akuvox E11 libvoice library provides unauthenticated access to the camera capture for image...
Critical
Unreviewed
CVE-2023-0349
was published
Mar 13, 2023
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the...
Critical
Unreviewed
CVE-2023-26957
was published
Mar 9, 2023
Improper Input Validation vulnerability in Eskom Bilgisayar e-Belediye allows Information...
Critical
Unreviewed
CVE-2023-1114
was published
Mar 1, 2023
An unauthenticated user can attach to an open interface exposed through JNDI by the Messaging...
Critical
Unreviewed
CVE-2022-41271
was published
Dec 13, 2022
Unauth. Arbitrary File Deletion vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
Critical
Unreviewed
CVE-2022-44584
was published
Nov 19, 2022
Authentication Bypass by Primary Weakness in GitHub repository kareadita/kavita prior to 0.6.0.3.
Critical
Unreviewed
CVE-2022-3993
was published
Nov 14, 2022
Missing Access Control vulnerability in PHP Crafts Accommodation System plugin <= 1.0.1 at...
Critical
Unreviewed
CVE-2022-37344
was published
Sep 7, 2022
Missing Access Control vulnerability in About Rentals. Inc. About Rentals plugin <= 1.5 at...
Critical
Unreviewed
CVE-2022-36427
was published
Sep 7, 2022
ProTip!
Advisories are also available from the
GraphQL API