GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,287
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,743
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
24,086 advisories
Filter by severity
An issue in Quectel BG96 BG96MAR02A08M1G allows attackers to bypass authentication via a crafted...
Critical
Unreviewed
CVE-2024-54984
was published
Dec 20, 2024
An issue in Quectel BC25 with firmware version BC25PAR01A06 allows attackers to bypass...
Critical
Unreviewed
CVE-2024-54982
was published
Dec 20, 2024
An issue in Quectel BC95-CNV V100R001C00SPC051 allows attackers to bypass authentication via a...
Critical
Unreviewed
CVE-2024-54983
was published
Dec 20, 2024
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos...
Critical
Unreviewed
CVE-2024-12728
was published
Dec 19, 2024
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall...
Critical
Unreviewed
CVE-2024-12727
was published
Dec 19, 2024
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB...
Critical
Unreviewed
CVE-2024-55081
was published
Dec 19, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-10244
was published
Dec 19, 2024
A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all...
Critical
Unreviewed
CVE-2021-26102
was published
Dec 19, 2024
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in...
Critical
Unreviewed
CVE-2024-12626
was published
Dec 19, 2024
Incorrect authorization vulnerability in HTTP POST method in Govee Home application on Android...
Critical
Unreviewed
CVE-2023-4617
was published
Dec 19, 2024
A unrestricted upload of file with dangerous type vulnerability in epaper draft function in...
Critical
Unreviewed
CVE-2024-11984
was published
Dec 19, 2024
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function...
Critical
Unreviewed
CVE-2024-55461
was published
Dec 19, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a...
Critical
Unreviewed
CVE-2024-56052
was published
Dec 18, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a...
Critical
Unreviewed
CVE-2024-56050
was published
Dec 18, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a...
Critical
Unreviewed
CVE-2024-56054
was published
Dec 18, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a...
Critical
Unreviewed
CVE-2024-56057
was published
Dec 18, 2024
In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due...
Critical
Unreviewed
CVE-2024-47038
was published
Dec 18, 2024
In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a...
Critical
Unreviewed
CVE-2024-47039
was published
Dec 18, 2024
There is a possible UAF due to a logic error in the code. This could lead to local escalation of...
Critical
Unreviewed
CVE-2024-47040
was published
Dec 18, 2024
Incorrect Privilege Assignment vulnerability in wpweb WooCommerce PDF Vouchers allows Privilege...
Critical
Unreviewed
CVE-2024-54383
was published
Dec 18, 2024
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
A denial-of-service and possible remote code execution vulnerability exists in the Rockwell...
Critical
Unreviewed
CVE-2024-12372
was published
Dec 18, 2024
A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The...
Critical
Unreviewed
CVE-2024-12373
was published
Dec 18, 2024
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This...
Critical
Unreviewed
CVE-2024-12371
was published
Dec 18, 2024
A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5...
Critical
Unreviewed
CVE-2023-34990
was published
Dec 18, 2024
ProTip!
Advisories are also available from the
GraphQL API