GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,457 advisories
Filter by severity
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
org.apache.iotdb:iotdb-core
(Maven)
May 14, 2025
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target...
Critical
Unreviewed
CVE-2025-32363
was published
May 14, 2025
iKuai8 v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
High
Unreviewed
CVE-2022-40469
was published
Oct 12, 2022
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload...
High
Unreviewed
CVE-2022-41534
was published
Oct 14, 2022
Brandon
Rothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi
did not have a...
Moderate
Unreviewed
CVE-2023-5677
was published
Feb 5, 2024
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is...
High
Unreviewed
CVE-2025-3053
was published
May 15, 2025
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an...
Moderate
Unreviewed
CVE-2025-0134
was published
May 14, 2025
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code...
Critical
Unreviewed
CVE-2015-2079
was published
Apr 28, 2025
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-4022
was published
Apr 28, 2025
Cosmos EVM Allows Partial Precompile State Writes
High
GHSA-mjfq-3qr2-6g84
was published
for
github.com/cosmos/evm
(Go)
May 14, 2025
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2025-45857
was published
May 13, 2025
The rphone module has a script that can be maliciously modified.Successful exploitation of this...
High
Unreviewed
CVE-2022-41576
was published
Oct 14, 2022
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2022-41544
was published
Oct 18, 2022
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on...
High
Unreviewed
CVE-2025-4428
was published
May 13, 2025
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper...
Low
Unreviewed
CVE-2025-23376
was published
Apr 28, 2025
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an...
High
Unreviewed
CVE-2025-43010
was published
May 13, 2025
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin...
Critical
Unreviewed
CVE-2025-44022
was published
May 12, 2025
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0....
Moderate
Unreviewed
CVE-2025-3982
was published
Apr 27, 2025
IPW Systems Metazo through 8.1.3 allows unauthenticated Remote Code Execution because...
Critical
Unreviewed
CVE-2025-46661
was published
Apr 28, 2025
OZI-Project/ozi-publish Code Injection vulnerability
Moderate
CVE-2025-47271
was published
for
OZI-Project/publish
(GitHub Actions)
May 12, 2025
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute...
Moderate
Unreviewed
CVE-2025-28201
was published
May 9, 2025
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of...
High
Unreviewed
CVE-2024-21683
was published
May 22, 2024
Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because...
High
Unreviewed
CVE-2023-22514
was published
Jan 16, 2024
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a...
Critical
Unreviewed
CVE-2025-29509
was published
May 9, 2025
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Critical
Unreviewed
CVE-2025-28203
was published
May 9, 2025
ProTip!
Advisories are also available from the
GraphQL API