GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
198 advisories
Filter by severity
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Critical
CVE-2018-20060
was published
for
urllib3
(pip)
Dec 12, 2018
http4k has a potential XXE (XML External Entity Injection) vulnerability
Critical
CVE-2024-55875
was published
for
org.http4k:http4k-format-xml
(Maven)
Dec 12, 2024
Label Studio has Hardcoded Django `SECRET_KEY` that can be Abused to Forge Session Tokens
Critical
CVE-2023-43791
was published
for
label-studio
(pip)
Nov 9, 2023
DIRAC's TokenManager does not check permissions on cached tokens
Critical
CVE-2024-24825
was published
for
DIRAC
(pip)
Feb 8, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3502
was published
Nov 14, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3501
was published
Nov 14, 2024
The CE21 Suite plugin for WordPress is vulnerable to sensitive information disclosure via the...
Critical
Unreviewed
CVE-2024-10285
was published
Nov 9, 2024
salt password information leaked in debug logs
Critical
CVE-2015-6941
was published
for
salt
(pip)
May 17, 2022
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that...
Critical
Unreviewed
CVE-2024-8884
was published
Oct 8, 2024
SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430,...
Critical
Unreviewed
CVE-2023-40622
was published
Sep 13, 2023
SQL Injection vulnerability in DerbyNet v9.0 allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2024-30922
was published
Apr 18, 2024
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the...
Critical
Unreviewed
CVE-2024-27113
was published
Sep 11, 2024
Django-Anymail prone to a timing attack
Critical
CVE-2018-6596
was published
for
django-anymail
(pip)
Jul 12, 2018
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10...
Critical
Unreviewed
CVE-2012-6664
was published
Jun 22, 2024
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Ariva Computer Accord...
Critical
Unreviewed
CVE-2024-1744
was published
Sep 6, 2024
A vulnerability that allows an attacker to access the NTLM hash of the Veeam Reporter Service...
Critical
Unreviewed
CVE-2024-42019
was published
Sep 7, 2024
An authentication bypass vulnerability can allow a low privileged attacker to access the NTLM...
Critical
Unreviewed
CVE-2024-38650
was published
Sep 7, 2024
An issue was discovered in ownCloud owncloud/graphapi 0.2.x before 0.2.1 and 0.3.x before 0.3.1....
Critical
Unreviewed
CVE-2023-49103
was published
Nov 22, 2023
The default credentials for the setup HSQL database (HSQLDB) for FileCatalyst Workflow are...
Critical
Unreviewed
CVE-2024-6633
was published
Aug 27, 2024
An issue was discovered in OpenClinic GA 5.247.01. An Unauthenticated File Download vulnerability...
Critical
Unreviewed
CVE-2023-40276
was published
Mar 19, 2024
A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with...
Critical
Unreviewed
CVE-2023-39337
was published
Nov 15, 2023
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to...
Critical
Unreviewed
CVE-2024-42394
was published
Aug 6, 2024
TightVNC (Server for Windows) before 2.8.84 allows attackers to connect to the control pipe via a...
Critical
Unreviewed
CVE-2024-42049
was published
Jul 28, 2024
An issue was discovered in OpenClinic GA 5.247.01. It allows retrieval of patient lists via...
Critical
Unreviewed
CVE-2023-40275
was published
Mar 19, 2024
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor...
Critical
Unreviewed
CVE-2024-27905
was published
Feb 27, 2024
ProTip!
Advisories are also available from the
GraphQL API