GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
73 advisories
Filter by severity
HkCms v2.3.2.240702 was discovered to contain an arbitrary file write vulnerability in the...
High
Unreviewed
CVE-2025-25761
was published
Feb 27, 2025
An authenticated file read vulnerability in the Palo Alto Networks PAN-OS software enables an...
High
Unreviewed
CVE-2025-0111
was published
Feb 12, 2025
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27944
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The bulk import...
High
Unreviewed
CVE-2024-27945
was published
May 14, 2024
A vulnerability has been identified in RUGGEDCOM CROSSBOW (All versions < V5.5). The affected...
High
Unreviewed
CVE-2024-27943
was published
May 14, 2024
PaddlePaddle allows arbitrary file read via paddle.vision.ops.read_file
High
CVE-2024-1603
was published
for
paddlepaddle
(pip)
Mar 23, 2024
The SMSA Shipping(official) plugin for WordPress is vulnerable to arbitrary file deletion due to...
High
Unreviewed
CVE-2024-12066
was published
Dec 21, 2024
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows...
High
Unreviewed
CVE-2024-4230
was published
Dec 19, 2024
External Control of File Name or Path vulnerability in PlexTrac allows Local Code Inclusion...
High
Unreviewed
CVE-2024-11838
was published
Dec 13, 2024
Externally Controlled Reference to a Resource in Another Sphere, Improper Input Validation, and External Control of File Name or Path in Ansible
High
CVE-2019-14905
was published
for
ansible
(pip)
Apr 20, 2021
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43615
was published
Oct 8, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43581
was published
Oct 8, 2024
Microsoft OpenSSH for Windows Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-38029
was published
Oct 8, 2024
There is a local file inclusion vulnerability in Esri Portal for ArcGIS 11.2. 11.1, 11.0 and 10.9...
High
Unreviewed
CVE-2024-38040
was published
Oct 4, 2024
Proxmox Virtual Environment is an open-source server management platform for enterprise...
High
Unreviewed
CVE-2024-21545
was published
Sep 25, 2024
Zoom VDI client installer prior to 5.14.0 contains an improper access control vulnerability. A...
High
Unreviewed
CVE-2023-28603
was published
Jun 13, 2023
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for...
High
Unreviewed
CVE-2024-7626
was published
Sep 11, 2024
An issue was discovered in Veritas Backup Exec before 22.2 HotFix 917391. The Backup Exec...
High
Unreviewed
CVE-2024-33671
was published
Apr 26, 2024
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows...
High
Unreviewed
CVE-2024-6255
was published
Jul 31, 2024
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local...
High
Unreviewed
CVE-2024-6714
was published
Jul 23, 2024
External Control of File Name or Path in GitHub repository stitionai/devika prior to -.
High
Unreviewed
CVE-2024-5334
was published
Jun 27, 2024
Remote code execution in web server context
High
CVE-2024-37295
was published
for
aimeos/aimeos-core
(Composer)
Jun 5, 2024
timber/timber vulnerable to Deserialization of Untrusted Data
High
CVE-2024-29800
was published
for
timber/timber
(Composer)
Apr 12, 2024
Windows HTML Platforms Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-20652
was published
Jan 9, 2024
A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics...
High
Unreviewed
CVE-2022-42734
was published
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API