GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
182 advisories
Filter by severity
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DAR-7000 up to 20230922. It...
Moderate
Unreviewed
CVE-2024-6525
was published
Jul 5, 2024
A vulnerability was found in ORIPA up to 1.72. It has been declared as critical. Affected by this...
Moderate
Unreviewed
CVE-2024-6441
was published
Jul 2, 2024
MENDELSON AS4 before 2024 B376 has a client-side vulnerability when a trading partner provides...
Moderate
Unreviewed
CVE-2024-39334
was published
Jun 24, 2024
The Universal Slider plugin for WordPress is vulnerable to PHP Object Injection in all versions...
Moderate
Unreviewed
CVE-2024-5649
was published
Jun 19, 2024
By-passing Protection of PharStreamWrapper Interceptor
Moderate
GHSA-4v5g-8pq2-32m2
was published
for
typo3/phar-stream-wrapper
(Composer)
Jun 5, 2024
Deserialization of Untrusted Data vulnerability in WebToffee Order Export & Order Import for...
Moderate
Unreviewed
CVE-2024-34751
was published
May 16, 2024
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found...
Moderate
Unreviewed
CVE-2024-4699
was published
May 14, 2024
Deserialization of Untrusted Data vulnerability in BdThemes Ultimate Store Kit Elementor Addons...
Moderate
Unreviewed
CVE-2024-4606
was published
May 14, 2024
Deserialization of Untrusted Data vulnerability in OCDI One Click Demo Import.This issue affects...
Moderate
Unreviewed
CVE-2024-34433
was published
May 14, 2024
The IBM SDK, Java Technology Edition's Object Request Broker (ORB) 7.1.0.0 through 7.1.5.21 and 8...
Moderate
Unreviewed
CVE-2023-38264
was published
May 14, 2024
kurwov vulnerable to Denial of Service due to improper data sanitization
Moderate
CVE-2024-34075
was published
for
kurwov
(npm)
May 3, 2024
The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX...
Moderate
Unreviewed
CVE-2024-3591
was published
May 1, 2024
Deserialization of Untrusted Data vulnerability in Team Yoast Custom field finder.This issue...
Moderate
Unreviewed
CVE-2024-33641
was published
Apr 29, 2024
Deserialization of Untrusted Data vulnerability in WebToffee Import Export WordPress Users.This...
Moderate
Unreviewed
CVE-2024-32835
was published
Apr 24, 2024
Deserialization of Untrusted Data vulnerability in Import and export users and customers.This...
Moderate
Unreviewed
CVE-2024-32817
was published
Apr 24, 2024
A vulnerability classified as critical has been found in Byzoro Smart S80 Management Platform up...
Moderate
Unreviewed
CVE-2024-4019
was published
Apr 20, 2024
Deserialization of Untrusted Data vulnerability in WP All Import Import Users from CSV.This issue...
Moderate
Unreviewed
CVE-2024-32431
was published
Apr 15, 2024
A vulnerability, which was classified as critical, has been found in cym1102 nginxWebUI up to 3.9...
Moderate
Unreviewed
CVE-2024-3740
was published
Apr 13, 2024
Deserialization of Untrusted Data vulnerability in PropertyHive.This issue affects PropertyHive:...
Moderate
Unreviewed
CVE-2024-27985
was published
Apr 11, 2024
A vulnerability was found in EyouCMS 1.6.5. It has been declared as critical. This vulnerability...
Moderate
Unreviewed
CVE-2024-3431
was published
Apr 8, 2024
Deserialization of Untrusted Data vulnerability in VJInfotech WP Import Export Lite.This issue...
Moderate
Unreviewed
CVE-2024-31308
was published
Apr 7, 2024
Deserialization of Untrusted Data vulnerability in WP Sunshine Sunshine Photo Cart.This issue...
Moderate
Unreviewed
CVE-2024-30221
was published
Mar 28, 2024
Gadget chain in Symfony 1 due to uncontrolled unserialized input in sfNamespacedParameterHolder
Moderate
CVE-2024-28861
was published
for
friendsofsymfony1/symfony1
(Composer)
Mar 22, 2024
`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code
Moderate
CVE-2024-29032
was published
for
qiskit-ibm-runtime
(pip)
Mar 20, 2024
Gadget chain in Symfony 1 due to vulnerable Swift Mailer dependency
Moderate
CVE-2024-28859
was published
for
friendsofsymfony1/swiftmailer
(Composer)
Mar 18, 2024
ProTip!
Advisories are also available from the
GraphQL API