GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,298 advisories
Filter by severity
Visual Studio Code Remote Code Execution Vulnerability
High
Unreviewed
CVE-2021-43891
was published
Dec 16, 2021
A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An...
High
Unreviewed
CVE-2021-29214
was published
Dec 11, 2021
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow...
High
Unreviewed
CVE-2010-3210
was published
May 17, 2022
Multiple PHP remote file inclusion vulnerabilities in Haudenschilt Family Connections CMS (FCMS)...
High
Unreviewed
CVE-2010-3419
was published
May 17, 2022
Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to...
High
Unreviewed
CVE-2010-3209
was published
May 17, 2022
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434...
High
Unreviewed
CVE-2020-25197
was published
Mar 19, 2022
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is...
High
Unreviewed
CVE-2022-0687
was published
Mar 22, 2022
The XML-RPC implementation on Cisco TelePresence Recording Server devices with software 1.6.x and...
High
Unreviewed
CVE-2011-0386
was published
May 17, 2022
Code Injection in CRI-O
High
CVE-2022-0811
was published
for
github.com/cri-o/cri-o
(Go)
Mar 15, 2022
Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad...
High
Unreviewed
CVE-2022-0944
was published
Mar 16, 2022
Server-side Template Injection in nystudio107/craft-seomatic
High
CVE-2021-44618
was published
for
nystudio107/craft-seomatic
(Composer)
Mar 12, 2022
Static Code Injection in Microweber
High
CVE-2022-0895
was published
for
microweber/microweber
(Composer)
Mar 11, 2022
The absence of filters when loading some sections in the web application of the vulnerable device...
High
Unreviewed
CVE-2022-22985
was published
Mar 11, 2022
The absence of filters when loading some sections in the web application of the vulnerable device...
High
Unreviewed
CVE-2022-24915
was published
Mar 11, 2022
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An...
High
Unreviewed
CVE-2022-34456
was published
Jan 18, 2023
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac...
High
Unreviewed
CVE-2022-42268
was published
Jan 13, 2023
Arbitrary JavaScript Execution in typed-function
High
CVE-2017-1001004
was published
for
typed-function
(npm)
Sep 2, 2020
Sandbox Breakout / Arbitrary Code Execution in static-eval
High
GHSA-x9hc-rw35-f44h
was published
for
static-eval
(npm)
Sep 2, 2020
Potential for Script Injection in syntax-error
High
CVE-2014-7192
was published
for
syntax-error
(npm)
Oct 24, 2017
Remote Code Execution in node-os-utils
High
GHSA-j9f8-8h89-j69x
was published
for
node-os-utils
(npm)
Jun 11, 2019
Command Injection in wiki-plugin-datalog
High
GHSA-pm52-wwrw-c282
was published
for
wiki-plugin-datalog
(npm)
Jun 13, 2019
ProTip!
Advisories are also available from the
GraphQL API