GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
149 advisories
Filter by severity
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an...
High
Unreviewed
CVE-2025-0111
was published
Feb 12, 2025
A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03....
Moderate
Unreviewed
CVE-2025-1225
was published
Feb 12, 2025
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database...
High
Unreviewed
CVE-2024-10979
was published
Nov 14, 2024
A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender...
High
Unreviewed
CVE-2023-6154
was published
Apr 1, 2024
php-svg-lib lacks path validation on font through SVG inline styles
Moderate
CVE-2024-25117
was published
for
phenx/php-svg-lib
(Composer)
Feb 21, 2024
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before...
Moderate
Unreviewed
CVE-2022-23439
was published
Jan 22, 2025
HCL MyXalytics is affected by out-of-band resource load (HTTP) vulnerability. An attacker can...
High
Unreviewed
CVE-2024-42168
was published
Jan 11, 2025
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.
High
Unreviewed
CVE-2022-30190
was published
Jun 2, 2022
In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a...
High
Unreviewed
CVE-2024-31319
was published
Jul 9, 2024
snapd failed to properly check the destination of symbolic links when extracting a snap
Low
CVE-2024-29069
was published
for
github.com/snapcore/snapd
(Go)
Jul 25, 2024
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
High
CVE-2019-14905
was published
for
ansible
(pip)
Apr 20, 2021
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This...
Moderate
Unreviewed
CVE-2024-5823
was published
Oct 29, 2024
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to...
Critical
Unreviewed
CVE-2023-5716
was published
Jan 19, 2024
HashiCorp Nomad vulnerable to symlink attacks
High
CVE-2024-1329
was published
for
github.com/hashicorp/nomad
(Go)
Feb 8, 2024
Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking
Moderate
CVE-2024-7625
was published
for
github.com/hashicorp/nomad
(Go)
Aug 15, 2024
Local privilege escalation during installation due to improper soft link handling. The following...
High
Unreviewed
CVE-2022-46869
was published
Aug 31, 2023
CVE-2024-45826 IMPACT
Due to improper input validation, a path traversal and remote code...
High
Unreviewed
CVE-2024-45826
was published
Sep 12, 2024
In certain highly specific configurations of the host system and MongoDB server binary...
Moderate
Unreviewed
CVE-2024-8207
was published
Aug 27, 2024
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been...
Moderate
Unreviewed
CVE-2024-7911
was published
Aug 18, 2024
A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute...
Moderate
Unreviewed
CVE-2024-6079
was published
Aug 13, 2024
Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an...
Moderate
Unreviewed
CVE-2024-28962
was published
Aug 6, 2024
HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during...
High
Unreviewed
CVE-2024-6717
was published
Jul 23, 2024
Windows Distributed Transaction Coordinator Remote Code Execution Vulnerability
Moderate
Unreviewed
CVE-2024-38049
was published
Jul 9, 2024
CometBFT is unstability during blocksync when syncing from malicious peer
Moderate
GHSA-hg58-rf2h-6rr7
was published
for
github.com/cometbft/cometbft
(Go)
Jun 28, 2024
Grafana Fine-grained access control vulnerability
Critical
CVE-2021-41244
was published
for
github.com/grafana/grafana
(Go)
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API