GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,339
Erlang
31
GitHub Actions
22
Go
2,099
Maven
5,000+
npm
3,763
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
920 advisories
Filter by severity
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Moderate
Unreviewed
CVE-2024-29991
was published
Apr 19, 2024
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute...
Moderate
Unreviewed
CVE-2023-51797
was published
Apr 19, 2024
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to...
Moderate
Unreviewed
CVE-2024-30567
was published
Apr 16, 2024
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to...
Moderate
Unreviewed
CVE-2024-31648
was published
Apr 15, 2024
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side...
Moderate
Unreviewed
CVE-2024-3785
was published
Apr 15, 2024
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side...
Moderate
Unreviewed
CVE-2024-3786
was published
Apr 15, 2024
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2023-6494
was published
Apr 13, 2024
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote...
Moderate
Unreviewed
CVE-2024-30845
was published
Apr 12, 2024
\An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute...
Moderate
Unreviewed
CVE-2023-44853
was published
Apr 12, 2024
Code injection in Apache Zeppelin Shell
Moderate
CVE-2024-31861
was published
for
org.apache.zeppelin:zeppelin-shell
(Maven)
Apr 11, 2024
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to...
Moderate
Unreviewed
CVE-2024-30878
was published
Apr 11, 2024
Leantime 3.0.6 is vulnerable to HTML Injection via /dashboard/show#/tickets/newTicket.
Moderate
Unreviewed
CVE-2024-27476
was published
Apr 10, 2024
A improper neutralization of special elements used in a template engine [CWE-1336] in...
Moderate
Unreviewed
CVE-2023-47542
was published
Apr 9, 2024
There is an HTML injection vulnerability in Esri Portal for ArcGIS <=11.0 that may allow a remote...
Moderate
Unreviewed
CVE-2024-25706
was published
Apr 4, 2024
Dolibarr ERP CRM Code Injection vulnerability during installation
Moderate
CVE-2024-29477
was published
for
dolibarr/dolibarr
(Composer)
Apr 3, 2024
Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to...
Moderate
Unreviewed
CVE-2024-31013
was published
Apr 3, 2024
Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2,...
Moderate
Unreviewed
CVE-2024-28005
was published
Mar 28, 2024
A user with administrative privileges can create a compromised dll file of the same name as the...
Moderate
Unreviewed
CVE-2024-2209
was published
Mar 27, 2024
Cross-site Scripting in Moodle Chat
Moderate
CVE-2024-28593
was published
for
moodle/moodle
(Composer)
Mar 22, 2024
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload...
Moderate
Unreviewed
CVE-2024-22724
was published
Mar 21, 2024
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the...
Moderate
Unreviewed
CVE-2024-2016
was published
Mar 21, 2024
An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the...
Moderate
Unreviewed
CVE-2024-25359
was published
Mar 21, 2024
Using a markup injection an attacker could have stolen nonce values. This could have been used to...
Moderate
Unreviewed
CVE-2024-2610
was published
Mar 19, 2024
A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue...
Moderate
Unreviewed
CVE-2024-2497
was published
Mar 15, 2024
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing...
Moderate
Unreviewed
CVE-2024-27627
was published
Mar 5, 2024
ProTip!
Advisories are also available from the
GraphQL API