GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,319
Erlang
31
GitHub Actions
21
Go
2,077
Maven
5,000+
npm
3,746
NuGet
674
pip
3,435
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
24,266 advisories
Filter by severity
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API...
Critical
Unreviewed
CVE-2024-11972
was published
Dec 31, 2024
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows...
Critical
Unreviewed
CVE-2024-12828
was published
Dec 30, 2024
TeamPass privileges issue
Critical
CVE-2024-50703
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API...
Critical
Unreviewed
CVE-2024-10044
was published
Dec 30, 2024
Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL...
Critical
Unreviewed
CVE-2024-47926
was published
Dec 30, 2024
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS...
Critical
Unreviewed
CVE-2024-47919
was published
Dec 30, 2024
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50716
was published
Dec 27, 2024
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50717
was published
Dec 27, 2024
SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
Critical
Unreviewed
CVE-2024-50713
was published
Dec 27, 2024
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is...
Critical
Unreviewed
CVE-2024-54450
was published
Dec 27, 2024
Integer overflow vulnerability exists in SimplCommerce at commit...
Critical
Unreviewed
CVE-2024-50944
was published
Dec 27, 2024
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script...
Critical
Unreviewed
CVE-2024-12652
was published
Dec 26, 2024
oc_huff_tree_unpack in huffdec.c in libtheora in Theora through 1.0 7180717 has an invalid...
Critical
Unreviewed
CVE-2024-56431
was published
Dec 25, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-8950
was published
Dec 25, 2024
Apache MINA Deserialization RCE Vulnerability
Critical
CVE-2024-52046
was published
for
org.apache.mina:mina-core
(Maven)
Dec 25, 2024
The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all...
Critical
Unreviewed
CVE-2024-11281
was published
Dec 25, 2024
Apache HugeGraph-Server: Fixed JWT Token (Secret)
Critical
CVE-2024-43441
was published
for
org.apache.hugegraph:hugegraph-server
(Maven)
Dec 24, 2024
Gogs has an argument Injection in the built-in SSH server
Critical
CVE-2024-39930
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Gogs allows argument injection during the previewing of changes
Critical
CVE-2024-39932
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Gogs allows deletion of internal files
Critical
CVE-2024-39931
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
SQL injection in Apache Traffic Control
Critical
CVE-2024-45387
was published
for
github.com/apache/trafficcontrol/v8
(Go)
Dec 23, 2024
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can...
Critical
Unreviewed
CVE-2024-40896
was published
Dec 23, 2024
Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be...
Critical
Unreviewed
CVE-2024-46873
was published
Dec 23, 2024
The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to,...
Critical
Unreviewed
CVE-2024-11349
was published
Dec 21, 2024
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote...
Critical
Unreviewed
CVE-2024-55509
was published
Dec 20, 2024
ProTip!
Advisories are also available from the
GraphQL API