GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
25,852 advisories
Filter by severity
Transparent TLS may not be applied to Marbles with certain manifest configurations
Critical
GHSA-x5r5-2qrx-rqj8
was published
for
github.com/edgelesssys/marblerun
(Go)
Feb 27, 2024
Dell Networking X-Series firmware versions prior to 3.0.1.8 contain an authentication bypass...
Critical
Unreviewed
CVE-2021-36320
was published
Nov 21, 2021
Suricata before 5.0.8 and 6.x before 6.0.4 allows TCP evasion via a client with a crafted TCP/IP...
Critical
Unreviewed
CVE-2021-37592
was published
Nov 20, 2021
SQL injection vulnerability in adv radius v.2.2.5 allows a local attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-22923
was published
Feb 13, 2024
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin...
Critical
Unreviewed
CVE-2024-1698
was published
Feb 27, 2024
Should an instance of AnythingLLM be hosted on an internal network and the attacked be explicitly...
Critical
Unreviewed
CVE-2024-0759
was published
Feb 27, 2024
@nfid/embed has compromised private key due to @dfinity/auth-client producing insecure session keys
Critical
GHSA-84c3-j8r2-mcm8
was published
for
@nfid/embed
(npm)
Feb 26, 2024
SAML authentication bypass due to missing validation on unsigned SAML messages
Critical
GHSA-hx5q-v6pj-533r
was published
for
com.linecorp.centraldogma:centraldogma-server-auth-saml
(Maven)
Feb 26, 2024
Armeria SAML authentication bypass due to missing validation on unsigned SAML messages
Critical
CVE-2024-1735
was published
for
com.linecorp.armeria:armeria-saml
(Maven)
Feb 26, 2024
The inclusion of the web scraper for AnythingLLM means that any user with the proper...
Critical
Unreviewed
CVE-2024-0455
was published
Feb 26, 2024
Attacker, with permission to submit a link or submits a link via POST to be collected that is...
Critical
Unreviewed
CVE-2024-0440
was published
Feb 26, 2024
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep...
Critical
Unreviewed
CVE-2023-5841
was published
Feb 1, 2024
libjwt 1.15.3 uses strcmp (which is not constant time) to verify authentication, which makes it...
Critical
Unreviewed
CVE-2024-25189
was published
Feb 8, 2024
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the taskID...
Critical
Unreviewed
CVE-2024-25220
was published
Feb 14, 2024
Atmail v6.6.0 was discovered to contain a SQL injection vulnerability via the username parameter...
Critical
Unreviewed
CVE-2024-24133
was published
Feb 7, 2024
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles...
Critical
Unreviewed
CVE-2022-48328
was published
Feb 20, 2023
Task Manager App v1.0 was discovered to contain a SQL injection vulnerability via the projectID...
Critical
Unreviewed
CVE-2024-25222
was published
Feb 14, 2024
SQL injection vulnerability in InnovaDeluxe "Manufacturer or supplier alphabetical search" ...
Critical
Unreviewed
CVE-2023-46350
was published
Feb 9, 2024
php-jwt 1.0.0 uses strcmp (which is not constant time) to verify authentication, which makes it...
Critical
Unreviewed
CVE-2024-25191
was published
Feb 8, 2024
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-24321
was published
Feb 8, 2024
In LiteSpeed QUIC (LSQUIC) Library before 4.0.4, DCID validation is mishandled.
Critical
Unreviewed
CVE-2024-25678
was published
Feb 9, 2024
SQL injection vulnerability in Presta Monster "Multi Accessories Pro" (hsmultiaccessoriespro)...
Critical
Unreviewed
CVE-2023-50026
was published
Feb 9, 2024
SQL Injection vulnerability in Boostmyshop (boostmyshopagent) module for Prestashop versions 1.1...
Critical
Unreviewed
CVE-2024-24308
was published
Feb 9, 2024
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42...
Critical
Unreviewed
CVE-2023-40266
was published
Feb 9, 2024
ProTip!
Advisories are also available from the
GraphQL API