GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,126
Maven
5,000+
npm
3,787
NuGet
683
pip
3,467
Pub
12
RubyGems
894
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
21,399 advisories
Filter by severity
In Apache Ignite versions from 2.6.0 and before 2.17.0, configured Class Serialization Filters...
Critical
Unreviewed
CVE-2024-52577
was published
Feb 14, 2025
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability...
Critical
Unreviewed
CVE-2025-22630
was published
Feb 14, 2025
The Dingtian DT-R0 Series is vulnerable to an exploit that allows
attackers to bypass login...
Critical
Unreviewed
CVE-2025-1283
was published
Feb 14, 2025
mySCADA myPRO Manager
is vulnerable to an OS command injection which could allow a remote...
Critical
Unreviewed
CVE-2025-25067
was published
Feb 14, 2025
mySCADA myPRO Manager
stores credentials in cleartext, which could allow an attacker to obtain...
Critical
Unreviewed
CVE-2025-22896
was published
Feb 14, 2025
The administrative web interface of
mySCADA myPRO Manager
can be accessed without...
Critical
Unreviewed
CVE-2025-24865
was published
Feb 14, 2025
SQL Injection vulnerability in audit/class.audit.php in osTicket osTicket-plugins before commit...
Critical
Unreviewed
CVE-2022-31890
was published
Apr 6, 2023
A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record...
Critical
Unreviewed
CVE-2025-25388
was published
Feb 13, 2025
The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged...
Critical
Unreviewed
CVE-2025-1127
was published
Feb 13, 2025
The CloudStack integration API service allows running its unauthenticated API server (usually on...
Critical
Unreviewed
CVE-2024-39864
was published
Jul 5, 2024
Increasing the resolution of video frames, while performing a multi-threaded encode, can result...
Critical
Unreviewed
CVE-2023-6879
was published
Dec 28, 2023
Pre-auth RCE in Apache Ofbiz 18.12.09.
It's due to XML-RPC no longer maintained still present....
Critical
Unreviewed
CVE-2023-49070
was published
Dec 5, 2023
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy
handshake.
When curl is...
Critical
Unreviewed
CVE-2023-38545
was published
Oct 18, 2023
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user...
Critical
Unreviewed
CVE-2023-30801
was published
Oct 10, 2023
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks,...
Critical
Unreviewed
CVE-2023-34124
was published
Jul 13, 2023
In PHP 8.0.X before 8.0.28, 8.1.X before 8.1.16 and 8.2.X before 8.2.3, core path resolution...
Critical
Unreviewed
CVE-2023-0568
was published
Feb 16, 2023
Improper Input Validation vulnerability in OTRS AG OTRS, OTRS AG ((OTRS)) Community Edition...
Critical
Unreviewed
CVE-2022-4427
was published
Dec 19, 2022
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a
possible way to access...
Critical
Unreviewed
CVE-2023-48418
was published
Jan 3, 2024
Brocade SANnav Web interface before Brocade SANnav v2.3.0 and v2.2.2a
allows remote...
Critical
Unreviewed
CVE-2023-31424
was published
Aug 31, 2023
Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of...
Critical
Unreviewed
CVE-2023-34416
was published
Jun 19, 2023
Memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory...
Critical
Unreviewed
CVE-2023-32216
was published
Jun 19, 2023
An issue was discovered in Samsung Exynos Mobile Processor and Baseband Modem Processor for...
Critical
Unreviewed
CVE-2023-28613
was published
Apr 4, 2023
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_495220...
Critical
Unreviewed
CVE-2023-24800
was published
Apr 7, 2023
D-Link DIR878 DIR_878_FW120B05 was discovered to contain a stack overflow in the sub_48AF78...
Critical
Unreviewed
CVE-2023-24799
was published
Apr 7, 2023
ProTip!
Advisories are also available from the
GraphQL API