GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,419
Maven
5,000+
npm
4,055
NuGet
723
pip
3,847
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
63 advisories
Filter by severity
Account users in Apache CloudStack by default are allowed to upload and register templates for...
High
Unreviewed
CVE-2024-45219
was published
Oct 16, 2024
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with...
High
Unreviewed
CVE-2024-38473
was published
Jul 1, 2024
Yandex Browser Lite for Android before 21.1.0 allows remote attackers to spoof the address bar.
High
Unreviewed
CVE-2021-25254
was published
May 21, 2025
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can...
High
Unreviewed
CVE-2022-41322
was published
Sep 25, 2022
A vulnerability exists in PX Backup whereby sensitive information may be logged under specific...
High
Unreviewed
CVE-2025-1308
was published
May 20, 2025
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as...
High
Unreviewed
CVE-2022-25235
was published
Feb 17, 2022
A vulnerability in the “Manages app data” functionality of the web application of ctrlX OS allows...
High
Unreviewed
CVE-2025-24338
was published
Apr 30, 2025
Multiple functions in NetApp OnCommand System Manager before 8.3.2 do not properly escape special...
High
Unreviewed
CVE-2016-3063
was published
May 17, 2022
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped...
High
Unreviewed
CVE-2022-22744
was published
Dec 22, 2022
SVG's <code><use></code> element could have been used to load unexpected content that could...
High
Unreviewed
CVE-2022-28284
was published
Dec 22, 2022
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0...
High
Unreviewed
CVE-2024-12368
was published
Feb 25, 2025
PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to...
High
Unreviewed
CVE-2022-30351
was published
Mar 30, 2023
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a...
High
Unreviewed
CVE-2023-29543
was published
Jun 2, 2023
A vulnerability was found in Romain Bourdon Wampserver all versions (discovered in v3.2.3 and v3...
High
Unreviewed
CVE-2024-46547
was published
Dec 9, 2024
In ArrayConcatVisitor of builtins-array.cc, there is a possible type confusion due to improper...
High
Unreviewed
CVE-2018-9433
was published
Nov 20, 2024
Sharp and Toshiba Tec MFPs improperly process query parameters in HTTP requests, which may allow...
High
Unreviewed
CVE-2024-47549
was published
Oct 25, 2024
Denial of Service (DoS) vulnerability in the DMS module. Successful exploitation of this...
High
Unreviewed
CVE-2023-52098
was published
Jan 16, 2024
Vulnerability of parameters being not verified in the WMS module. Successful exploitation of this...
High
Unreviewed
CVE-2023-52102
was published
Jan 16, 2024
Interactive Forms (IAF) in GX Software XperienCentral versions 10.33.1 until 10.35.0 was...
High
Unreviewed
CVE-2022-43713
was published
Jul 26, 2023
Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a...
High
Unreviewed
CVE-2023-28738
was published
Jan 19, 2024
Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability...
High
Unreviewed
CVE-2022-36392
was published
Aug 11, 2023
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
High
Unreviewed
CVE-2024-9348
was published
Oct 16, 2024
HAProxy before 2.8.2 accepts # as part of the URI component, which might allow remote attackers...
High
Unreviewed
CVE-2023-45539
was published
Nov 28, 2023
An unauthenticated local attacker can gain admin privileges by deploying a config file due to...
High
Unreviewed
CVE-2024-45271
was published
Oct 15, 2024
Input verification vulnerability in the audio module. Successful exploitation of this...
High
Unreviewed
CVE-2023-39382
was published
Aug 13, 2023
ProTip!
Advisories are also available from the
GraphQL API