GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
3,934 advisories
Filter by severity
The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader)...
High
Unreviewed
CVE-2024-42041
was published
Oct 30, 2024
An issue in Ethereum v.1.12.2 allows remote attacker to execute arbitrary code via the PepeGxng...
Critical
Unreviewed
CVE-2024-51427
was published
Oct 30, 2024
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side...
Moderate
Unreviewed
CVE-2024-3785
was published
Apr 15, 2024
CycloneDX cdxgen may execute code contained within build-related files
Moderate
CVE-2024-50611
was published
for
@cyclonedx/cdxgen
(npm)
Oct 28, 2024
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the...
Critical
Unreviewed
CVE-2023-38198
was published
Jul 13, 2023
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin...
Critical
Unreviewed
CVE-2024-48138
was published
Oct 30, 2024
OS Command Injection in Snyk gradle plugin
High
CVE-2024-48964
was published
for
snyk-gradle-plugin
(npm)
Oct 23, 2024
The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-9846
was published
Oct 30, 2024
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the...
Moderate
Unreviewed
CVE-2024-10505
was published
Oct 30, 2024
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the...
Moderate
Unreviewed
CVE-2024-48236
was published
Oct 26, 2024
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of...
Moderate
Unreviewed
CVE-2024-48235
was published
Oct 26, 2024
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to...
High
Unreviewed
CVE-2024-48700
was published
Oct 25, 2024
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js...
High
Unreviewed
CVE-2024-48655
was published
Oct 25, 2024
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI)...
Critical
Unreviewed
CVE-2024-37846
was published
Oct 25, 2024
ServiceNow has addressed an input validation vulnerability that was identified in the Now...
Critical
Unreviewed
CVE-2024-8923
was published
Oct 29, 2024
pyload-ng vulnerable to RCE with js2py sandbox escape
Critical
CVE-2024-39205
was published
for
pyload-ng
(pip)
Sep 9, 2024
sqla-yaml-fixtures is vulnerable to Code Injection
High
CVE-2019-3575
was published
for
sqla-yaml-fixtures
(pip)
Jan 4, 2019
Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console...
Critical
Unreviewed
CVE-2024-50498
was published
Oct 28, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson...
High
Unreviewed
CVE-2024-50492
was published
Oct 28, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress...
High
Unreviewed
CVE-2024-50450
was published
Oct 28, 2024
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code...
High
Unreviewed
CVE-2024-9162
was published
Oct 28, 2024
Remote Code Execution in Red Discord Bot
High
CVE-2020-15147
was published
for
Red-DiscordBot
(pip)
Aug 21, 2020
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-9772
was published
Oct 26, 2024
Privilege escalation for users that can access mock configuration
Moderate
CVE-2023-6395
was published
for
templated_dictionary
(pip)
Jan 16, 2024
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a...
Critical
Unreviewed
CVE-2024-48579
was published
Oct 25, 2024
ProTip!
Advisories are also available from the
GraphQL API