GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
944 advisories
Filter by severity
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add...
Critical
Unreviewed
CVE-2017-11167
was published
May 17, 2022
Code Injection in SEOmatic
Critical
CVE-2021-41749
was published
for
nystudio107/craft-seomatic
(Composer)
Jun 13, 2022
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a...
Critical
Unreviewed
CVE-2022-30877
was published
Jun 9, 2022
job/uploadfile_save.php in MetInfo through 5.3.17 blocks the .php extension but not related...
Critical
Unreviewed
CVE-2017-11715
was published
May 17, 2022
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller...
Critical
Unreviewed
CVE-2020-21651
was published
May 24, 2022
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
Critical
Unreviewed
CVE-2021-45983
was published
Jun 3, 2022
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller...
Critical
Unreviewed
CVE-2020-21652
was published
May 24, 2022
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute...
Critical
Unreviewed
CVE-2020-22937
was published
May 24, 2022
An arbitrary code execution vulnerability exists in Micro Focus Application Performance...
Critical
Unreviewed
CVE-2021-22514
was published
May 24, 2022
Execute arbitrary code vulnerability in Micro Focus SiteScope product, affecting versions 11.40...
Critical
Unreviewed
CVE-2021-22519
was published
May 24, 2022
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4...
Critical
Unreviewed
CVE-2020-25414
was published
May 24, 2022
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request...
Critical
Unreviewed
CVE-2021-26810
was published
May 24, 2022
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
Critical
Unreviewed
CVE-2020-21784
was published
May 24, 2022
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through...
Critical
Unreviewed
CVE-2020-10666
was published
May 24, 2022
@pendo324/get-process-by-name are vulnerable to Arbitrary Code Execution
Critical
CVE-2022-25644
was published
for
@pendo324/get-process-by-name
(npm)
Aug 29, 2022
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with...
Critical
Unreviewed
CVE-2021-20623
was published
May 24, 2022
morgan-json vulnerable to Arbitrary Code Execution
Critical
CVE-2022-25921
was published
for
morgan-json
(npm)
Aug 29, 2022
PaddlePaddle vulnerable to code injection via winstr
Critical
CVE-2022-45908
was published
for
paddlepaddle
(pip)
Nov 26, 2022
There is a logic bypass vulnerability in smartphones. Successful exploitation of this...
Critical
Unreviewed
CVE-2021-22430
was published
Feb 26, 2022
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability...
Critical
Unreviewed
CVE-2022-22954
was published
Apr 12, 2022
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for...
Critical
Unreviewed
CVE-2020-15591
was published
Mar 18, 2022
Microsoft Defender for IoT Remote Code Execution Vulnerability This CVE ID is unique from CVE...
Critical
Unreviewed
CVE-2021-42310
was published
Dec 16, 2021
Bot Framework SDK Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2021-43225
was published
Dec 16, 2021
Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2021-43899
was published
Dec 16, 2021
ProTip!
Advisories are also available from the
GraphQL API