GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,978
Erlang
29
GitHub Actions
16
Go
1,768
Maven
4,991
npm
3,537
NuGet
616
pip
3,107
Pub
10
RubyGems
837
Rust
786
Swift
34
Unreviewed advisories
All unreviewed
5,000+
94,400 advisories
Filter by severity
Nuclei Path Traversal vulnerability
High
CVE-2023-37896
was published
for
github.com/projectdiscovery/nuclei
(Go)
Aug 4, 2023
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The...
High
Unreviewed
CVE-2023-29505
was published
Aug 4, 2023
Fujitsu Software Infrastructure Manager (ISM) stores sensitive information at the product's...
High
Unreviewed
CVE-2023-39379
was published
Aug 4, 2023
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in...
High
Unreviewed
CVE-2023-4141
was published
Aug 4, 2023
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in...
High
Unreviewed
CVE-2023-4140
was published
Aug 4, 2023
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in...
High
Unreviewed
CVE-2023-4142
was published
Aug 4, 2023
Assmann Digitus Plug&View IP Camera family allows unauthenticated attackers to download a copy of...
High
Unreviewed
CVE-2023-30146
was published
Aug 4, 2023
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure...
High
Unreviewed
CVE-2023-4139
was published
Aug 4, 2023
Insecure access control in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to read...
High
Unreviewed
CVE-2023-38952
was published
Aug 4, 2023
Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27...
High
Unreviewed
CVE-2023-0525
was published
Aug 4, 2023
User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during...
High
Unreviewed
CVE-2023-36135
was published
Aug 4, 2023
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to...
High
Unreviewed
CVE-2023-30297
was published
Aug 4, 2023
A path traversal vulnerability in the iclock API of ZKTeco BioTime v8.5.5 allows unauthenticated...
High
Unreviewed
CVE-2023-38950
was published
Aug 4, 2023
An issue in a hidden API in ZKTeco BioTime v8.5.5 allows unauthenticated attackers to arbitrarily...
High
Unreviewed
CVE-2023-38949
was published
Aug 4, 2023
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given...
High
Unreviewed
CVE-2023-37497
was published
Aug 4, 2023
A user is capable of assigning him/herself to arbitrary groups by reusing a POST request issued...
High
Unreviewed
CVE-2023-37498
was published
Aug 4, 2023
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types...
High
Unreviewed
CVE-2023-20216
was published
Aug 4, 2023
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin...
High
Unreviewed
CVE-2023-39121
was published
Aug 3, 2023
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files...
High
Unreviewed
CVE-2023-0956
was published
Aug 3, 2023
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows...
High
Unreviewed
CVE-2023-33363
was published
Aug 3, 2023
An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows...
High
Unreviewed
CVE-2023-33364
was published
Aug 3, 2023
An arbitrary file download vulnerability in the /c/PluginsController.php component of jizhi CMS 1...
High
Unreviewed
CVE-2023-38948
was published
Aug 3, 2023
A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows...
High
Unreviewed
CVE-2023-33366
was published
Aug 3, 2023
Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local...
High
Unreviewed
CVE-2023-32764
was published
Aug 3, 2023
A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows...
High
Unreviewed
CVE-2023-33365
was published
Aug 3, 2023
ProTip!
Advisories are also available from the
GraphQL API