GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,757
Erlang
35
GitHub Actions
29
Go
2,327
Maven
5,000+
npm
3,960
NuGet
712
pip
3,741
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
22,538 advisories
Filter by severity
Web Based Quiz System v1.0 was discovered to contain a SQL injection vulnerability via the qid...
Critical
Unreviewed
CVE-2022-35422
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34953
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34951
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34946
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34950
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34948
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34947
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34945
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities...
Critical
Unreviewed
CVE-2022-34949
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34952
was published
Aug 3, 2022
Pharmacy Management System v1.0 was discovered to contain a SQL injection vulnerability via the...
Critical
Unreviewed
CVE-2022-34954
was published
Aug 3, 2022
This affects all versions of package s3-kilatstorage.
Critical
Unreviewed
CVE-2020-28424
was published
Aug 3, 2022
Mealie 1.0.0beta3 contains an arbitrary file upload vulnerability which allows attackers to...
Critical
Unreviewed
CVE-2022-34613
was published
Aug 3, 2022
EasyUse MailHunter Ultimate’s cookie deserialization function has an inadequate validation...
Critical
Unreviewed
CVE-2022-35223
was published
Aug 3, 2022
In Quest KACE Systems Management Appliance (SMA) through 12.0, a hash collision is possible...
Critical
Unreviewed
CVE-2022-30285
was published
Aug 3, 2022
A SQL injection vulnerability exists within Quest KACE Systems Management Appliance (SMA) through...
Critical
Unreviewed
CVE-2022-29807
was published
Aug 3, 2022
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4...
Critical
Unreviewed
CVE-2022-31775
was published
Aug 2, 2022
In Realtek eCos RSDK 1.5.7p1 and MSDK 4.9.4p1, the SIP ALG function that rewrites SDP data has a...
Critical
Unreviewed
CVE-2022-27255
was published
Aug 2, 2022
The Youzify WordPress plugin before 1.2.0 does not sanitise and escape a parameter before using...
Critical
Unreviewed
CVE-2022-1950
was published
Aug 2, 2022
The Simple Membership WordPress plugin before 4.1.3 allows user to change their membership at the...
Critical
Unreviewed
CVE-2022-2317
was published
Aug 2, 2022
In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead...
Critical
Unreviewed
CVE-2022-26437
was published
Aug 2, 2022
Improper Authorization in GitHub repository kromitgmbh/titra prior to 0.79.1.
Critical
Unreviewed
CVE-2022-2595
was published
Aug 2, 2022
The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation,...
Critical
Unreviewed
CVE-2022-31321
was published
Aug 2, 2022
EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application...
Critical
Unreviewed
CVE-2022-30083
was published
Jul 31, 2022
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug...
Critical
Unreviewed
CVE-2022-1799
was published
Jul 30, 2022
ProTip!
Advisories are also available from the
GraphQL API