GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
2,346 advisories
Filter by severity
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14,...
High
Unreviewed
CVE-2023-42833
was published
Jan 11, 2024
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password...
High
Unreviewed
CVE-2024-51329
was published
Nov 4, 2024
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-10263
was published
Nov 5, 2024
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE)...
High
Unreviewed
CVE-2024-37845
was published
Oct 25, 2024
lilconfig Code Injection vulnerability
High
CVE-2024-21537
was published
for
lilconfig
(npm)
Oct 31, 2024
The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader)...
High
Unreviewed
CVE-2024-42041
was published
Oct 30, 2024
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control...
High
Unreviewed
CVE-2024-51243
was published
Oct 30, 2024
OS Command Injection in Snyk gradle plugin
High
CVE-2024-48964
was published
for
snyk-gradle-plugin
(npm)
Oct 23, 2024
The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-9846
was published
Oct 30, 2024
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to...
High
Unreviewed
CVE-2024-48700
was published
Oct 25, 2024
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js...
High
Unreviewed
CVE-2024-48655
was published
Oct 25, 2024
sqla-yaml-fixtures is vulnerable to Code Injection
High
CVE-2019-3575
was published
for
sqla-yaml-fixtures
(pip)
Jan 4, 2019
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson...
High
Unreviewed
CVE-2024-50492
was published
Oct 28, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress...
High
Unreviewed
CVE-2024-50450
was published
Oct 28, 2024
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code...
High
Unreviewed
CVE-2024-9162
was published
Oct 28, 2024
Remote Code Execution in Red Discord Bot
High
CVE-2020-15147
was published
for
Red-DiscordBot
(pip)
Aug 21, 2020
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-9772
was published
Oct 26, 2024
Code injection via unsafe YAML loading
High
CVE-2021-43811
was published
for
sockeye
(pip)
Dec 9, 2021
N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is...
High
Unreviewed
CVE-2024-47158
was published
Oct 25, 2024
An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote...
High
Unreviewed
CVE-2023-33472
was published
Jan 13, 2024
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS...
High
Unreviewed
CVE-2023-32418
was published
Jul 27, 2023
A vulnerability in the Web Interface component of Mitel MiCollab through 9.8 SP1 (9.8.1.5) and...
High
Unreviewed
CVE-2024-41714
was published
Oct 21, 2024
Poetry Argument Injection can lead to Local Code Execution
High
CVE-2022-36069
was published
for
poetry
(pip)
Sep 16, 2022
Microsoft Internet Explorer 5.01 SP4, 6, 6 SP1, 7, and 8 does not properly handle argument...
High
Unreviewed
CVE-2009-2529
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API