GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,097
Erlang
29
GitHub Actions
19
Go
1,925
Maven
5,000+
npm
3,657
NuGet
638
pip
3,264
Pub
10
RubyGems
873
Rust
823
Swift
35
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
285 advisories
Filter by severity
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15...
Moderate
Unreviewed
CVE-2023-3444
was published
Jul 13, 2023
This is a reflected cross site scripting vulnerability in the PaperCut NG/MF application server....
Moderate
Unreviewed
CVE-2024-1883
was published
Mar 14, 2024
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow...
Moderate
Unreviewed
CVE-2023-4393
was published
Oct 30, 2023
Couchbase Server 7.6.x before 7.6.2, 7.2.x before 7.2.6, and all earlier versions allows HTTP...
Moderate
Unreviewed
CVE-2024-25673
was published
Sep 19, 2024
Zoom clients prior to 5.13.10 contain an HTML injection vulnerability. A malicious user could...
Moderate
Unreviewed
CVE-2023-28599
was published
Jun 13, 2023
Zoom for Linux clients prior to 5.13.10 contain an HTML injection vulnerability. If a victim...
Moderate
Unreviewed
CVE-2023-28598
was published
Jun 13, 2023
Pega Platform versions 8.1 to Infinity 24.1.2 are affected by an HTML Injection issue with Stage.
Moderate
Unreviewed
CVE-2024-6702
was published
Sep 12, 2024
A Host header injection vulnerability in the password reset function of LimeSurvey v.6.6.1+240806...
Moderate
Unreviewed
CVE-2024-42903
was published
Sep 3, 2024
A low privileged remote attacker can perform configuration changes of the firewall services,...
Moderate
Unreviewed
CVE-2024-43393
was published
Sep 10, 2024
A low privileged remote attacker can perform configuration changes of the firewall services,...
Moderate
Unreviewed
CVE-2024-43392
was published
Sep 10, 2024
A low privileged remote attacker can perform configuration changes of the firewall services,...
Moderate
Unreviewed
CVE-2024-43391
was published
Sep 10, 2024
A low privileged remote attacker can perform configuration changes of the firewall services,...
Moderate
Unreviewed
CVE-2024-43390
was published
Sep 10, 2024
A low privileged remote attacker can perform configuration changes of the ospf service through...
Moderate
Unreviewed
CVE-2024-43389
was published
Sep 10, 2024
Fault Injection vulnerability in wc_ed25519_sign_msg function in wolfssl/wolfcrypt/src/ed25519.c...
Moderate
Unreviewed
CVE-2024-2881
was published
Aug 30, 2024
Fault Injection vulnerability in RsaPrivateDecryption function in wolfssl/wolfcrypt/src/rsa.c in...
Moderate
Unreviewed
CVE-2024-1545
was published
Aug 30, 2024
A vulnerability was found in HM Courts & Tribunals Service Probate Back Office up to...
Moderate
Unreviewed
CVE-2024-8367
was published
Sep 1, 2024
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or...
Moderate
Unreviewed
CVE-2023-6174
was published
Nov 16, 2023
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.1 and 11.5 is vulnerable to...
Moderate
Unreviewed
CVE-2024-31882
was published
Aug 14, 2024
A vulnerability was found in playSMS 1.4.3. It has been declared as problematic. Affected by this...
Moderate
Unreviewed
CVE-2024-6469
was published
Jul 3, 2024
A vulnerability was found in playSMS 1.4.3. It has been rated as problematic. Affected by this...
Moderate
Unreviewed
CVE-2024-6470
was published
Jul 3, 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up...
Moderate
Unreviewed
CVE-2021-22204
was published
May 24, 2022
A vulnerability in the web-based management interface of Cisco AsyncOS for Secure Email Gateway...
Moderate
Unreviewed
CVE-2024-20429
was published
Jul 17, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Moderate
Unreviewed
CVE-2024-38700
was published
Jul 12, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Moderate
Unreviewed
CVE-2024-35728
was published
Jun 10, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Moderate
Unreviewed
CVE-2024-35680
was published
Jun 10, 2024
ProTip!
Advisories are also available from the
GraphQL API