GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
23,712 advisories
Filter by severity
Powerjob >= 3.20 is vulnerable to SQL injection via the version parameter.
Critical
Unreviewed
CVE-2024-44546
was published
Nov 11, 2024
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in...
Critical
Unreviewed
CVE-2021-35473
was published
Nov 11, 2024
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-29382
was published
Jul 6, 2023
An issue in Zimbra Collaboration (ZCS) v.8.8.15 and v.9.0 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2023-29381
was published
Jul 6, 2023
Apache Airflow vulnerable to Privilege Context Switching Error
Critical
CVE-2023-25754
was published
for
apache-airflow
(pip)
May 8, 2023
xalpha vulnerable to Remote Code Execution
Critical
CVE-2023-37659
was published
for
xalpha
(pip)
Jul 11, 2023
Zope Object Database (ZODB) Arbitrary files reading and deletion
Critical
CVE-2009-2701
was published
for
zodb3
(pip)
May 2, 2022
Zope Object Database (ZODB) vulnerable to arbitrary Python code execution in ZEO storage servers
Critical
CVE-2009-0668
was published
for
ZODB3
(pip)
May 2, 2022
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection')...
Critical
Unreviewed
CVE-2024-47208
was published
Nov 18, 2024
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of...
Critical
Unreviewed
CVE-2024-50919
was published
Nov 18, 2024
AVSCMS v8.2.0 was discovered to contain weak default credentials for the Administrator account.
Critical
Unreviewed
CVE-2024-51051
was published
Nov 19, 2024
An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated...
Critical
Unreviewed
CVE-2024-0012
was published
Nov 18, 2024
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build...
Critical
Unreviewed
CVE-2024-25255
was published
Nov 12, 2024
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to...
Critical
Unreviewed
CVE-2023-52268
was published
Nov 12, 2024
Cross-Site Request Forgery (CSRF) vulnerability in 荒野无灯 Hacklog DownloadManager allows Upload a...
Critical
Unreviewed
CVE-2024-52401
was published
Nov 19, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Cliconomics Exclusive Content Password Protect...
Critical
Unreviewed
CVE-2024-52402
was published
Nov 19, 2024
An arbitrary file upload vulnerability in the component /main/fileupload.php of AVSCMS v8.2.0...
Critical
Unreviewed
CVE-2024-51053
was published
Nov 18, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3502
was published
Nov 14, 2024
In lunary-ai/lunary versions up to and including 1.2.5, an information disclosure vulnerability...
Critical
Unreviewed
CVE-2024-3501
was published
Nov 14, 2024
Apache Tomcat - Authentication Bypass
Critical
CVE-2024-52316
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Nov 18, 2024
Inconsistent Interpretation of HTTP Requests in twisted.web
Critical
CVE-2022-24801
was published
for
twisted
(pip)
Apr 4, 2022
Incorrect threshold signature computation in TUF
Critical
CVE-2020-6174
was published
for
tuf
(pip)
Aug 21, 2020
Exposure of Sensitive Information to an Unauthorized Actor in urllib3
Critical
CVE-2018-20060
was published
for
urllib3
(pip)
Dec 12, 2018
ProTip!
Advisories are also available from the
GraphQL API