GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
2,237 advisories
Filter by severity
ZrLog 2.2.2 has a remote command execution vulnerability at plugin download function, it could...
High
Unreviewed
CVE-2021-44094
was published
Nov 29, 2021
Zoho ManageEngine M365 Manager Plus before 4421 is vulnerable to file-upload remote code execution.
Critical
Unreviewed
CVE-2021-42099
was published
Dec 1, 2021
Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s...
High
Unreviewed
CVE-2021-42123
was published
Dec 1, 2021
An arbitrary file upload vulnerability in Z-BlogPHP v1.6.1.2100 allows attackers to execute...
High
Unreviewed
CVE-2020-29176
was published
Dec 4, 2021
The software allows the attacker to upload or transfer files of dangerous types to the WebHMI...
Critical
Unreviewed
CVE-2021-43936
was published
Dec 7, 2021
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an...
High
Unreviewed
CVE-2021-42125
was published
Dec 8, 2021
A privilege escalation vulnerability exists in the Remote Server functionality of Dream Report...
High
Unreviewed
CVE-2021-21957
was published
Dec 9, 2021
PineApp - Mail Secure - The attacker must be logged in as a user to the Pineapp system. The...
High
Unreviewed
CVE-2021-36719
was published
Dec 9, 2021
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior...
High
Unreviewed
CVE-2021-27860
was published
Dec 9, 2021
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading...
High
Unreviewed
CVE-2021-27984
was published
Dec 11, 2021
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution...
Critical
Unreviewed
CVE-2021-43117
was published
Dec 14, 2021
A Remote Code Execution (RCE) vulnerability exists in emlog 5.3.1 via content/plugins.
Critical
Unreviewed
CVE-2021-40883
was published
Dec 15, 2021
OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an...
Critical
Unreviewed
CVE-2021-41560
was published
Dec 16, 2021
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An...
High
Unreviewed
CVE-2021-41870
was published
Dec 16, 2021
The "Log alert to a file" action within action management enables any Orion Platform user with...
High
Unreviewed
CVE-2021-35244
was published
Dec 21, 2021
Chain Sea ai chatbot system’s file upload function has insufficient filtering for special...
Critical
Unreviewed
CVE-2021-44164
was published
Dec 21, 2021
4MOSAn GCB Doctor’s file upload function has improper user privilege control. A remote attacker...
Critical
Unreviewed
CVE-2021-44159
was published
Dec 21, 2021
An issue was discovered in Quest KACE Desktop Authority before 11.2. /dacomponentui/profiles...
Critical
Unreviewed
CVE-2021-44031
was published
Dec 23, 2021
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management...
Moderate
Unreviewed
CVE-2021-46078
was published
Jan 7, 2022
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management...
High
Unreviewed
CVE-2021-46079
was published
Jan 7, 2022
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker...
High
Unreviewed
CVE-2021-46076
was published
Jan 7, 2022
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows...
High
Unreviewed
CVE-2021-43973
was published
Jan 12, 2022
In Sourcecodetester Printable Staff ID Card Creator System 1.0 after compromising the database...
Critical
Unreviewed
CVE-2021-45411
was published
Jan 13, 2022
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the...
High
Unreviewed
CVE-2021-44651
was published
Jan 13, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2021-34997
was published
Jan 14, 2022
ProTip!
Advisories are also available from the
GraphQL API