GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
99,167 advisories
Filter by severity
Project files may contain malicious contents which the software will use to create files on the...
High
Unreviewed
CVE-2022-45792
was published
Jan 22, 2024
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found...
High
Unreviewed
CVE-2024-0778
was published
Jan 22, 2024
Spring Framework server Web DoS Vulnerability
High
CVE-2024-22233
was published
for
org.springframework:spring-core
(Maven)
Jan 22, 2024
CloudLinux
CageFS 7.1.1-1 or below passes the authentication token as command line
argument. In...
High
Unreviewed
CVE-2020-36771
was published
Jan 22, 2024
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
High
Unreviewed
CVE-2024-22895
was published
Jan 22, 2024
chasquid HTTP Request/Response Smuggling vulnerability
High
CVE-2023-52354
was published
for
github.com/albertito/chasquid
(Go)
Jan 22, 2024
Technicolor TC8715D devices have predictable default WPA2 security passwords. An attacker who...
High
Unreviewed
CVE-2023-47352
was published
Jan 22, 2024
Dremio before 24.3.1 allows path traversal. An authenticated user who has no privileges on...
High
Unreviewed
CVE-2024-23768
was published
Jan 22, 2024
An issue was discovered in Mbed TLS through 3.5.1. In mbedtls_ssl_session_reset, the maximum...
High
Unreviewed
CVE-2023-52353
was published
Jan 22, 2024
An issue was discovered in Mbed TLS 3.5.1. There is persistent handshake denial if a client sends...
High
Unreviewed
CVE-2024-23744
was published
Jan 22, 2024
A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage...
High
Unreviewed
CVE-2023-6531
was published
Jan 21, 2024
Ubee DDW365 XCNDDW365 and DDW366 XCNDXW3WB devices have predictable default WPA2 PSKs that could...
High
Unreviewed
CVE-2024-23726
was published
Jan 21, 2024
The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form...
High
Unreviewed
CVE-2023-7063
was published
Jan 20, 2024
Cross Site Request Forgery vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker...
High
Unreviewed
CVE-2023-47024
was published
Jan 20, 2024
YonBIP v3_23.05 was discovered to contain an arbitrary file read vulnerability via the nc.bs...
High
Unreviewed
CVE-2023-51926
was published
Jan 20, 2024
A vulnerability, which was classified as critical, was found in Hecheng Leadshop up to 1.4.20....
High
Unreviewed
CVE-2024-0739
was published
Jan 20, 2024
SPV Merkle proof malleability allows the maintainer to prove invalid transactions
High
GHSA-wg2x-rv86-mmpx
was published
for
@keep-network/tbtc-v2
(npm)
Jan 19, 2024
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
High
CVE-2024-23331
was published
for
vite
(npm)
Jan 19, 2024
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local...
High
Unreviewed
CVE-2023-6043
was published
Jan 19, 2024
Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject...
High
Unreviewed
CVE-2023-49329
was published
Jan 19, 2024
Sandbox escape in Artemis Java Test Sandbox
High
CVE-2024-23681
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
Sandbox escape in Artemis Java Test Sandbox
High
CVE-2024-23682
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
Inefficient Algorithmic Complexity in com.upokecenter:cbor
High
CVE-2024-23684
was published
for
com.upokecenter:cbor
(Maven)
Jan 19, 2024
Sandbox escape in Artemis Java Test Sandbox
High
CVE-2024-23683
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Jan 19, 2024
ProTip!
Advisories are also available from the
GraphQL API