GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,991
Erlang
29
GitHub Actions
16
Go
1,779
Maven
5,000+
npm
3,544
NuGet
619
pip
3,134
Pub
10
RubyGems
838
Rust
793
Swift
34
Unreviewed advisories
All unreviewed
5,000+
110,256 advisories
Filter by severity
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E,...
Moderate
Unreviewed
CVE-2024-7120
was published
Jul 26, 2024
An issue was discovered by Elastic whereby Watcher search input logged the search query results...
Moderate
Unreviewed
CVE-2023-49921
was published
Jul 26, 2024
A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online...
Moderate
Unreviewed
CVE-2024-7119
was published
Jul 26, 2024
A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management...
Moderate
Unreviewed
CVE-2024-7118
was published
Jul 26, 2024
A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll...
Moderate
Unreviewed
CVE-2024-7117
was published
Jul 26, 2024
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via...
Moderate
Unreviewed
CVE-2024-4447
was published
Jul 26, 2024
A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-7114
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7116
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7115
was published
Jul 26, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38103
was published
Jul 26, 2024
The "reset password" login page accepted an HTML injection via URL parameters.
This has already...
Moderate
Unreviewed
CVE-2024-3938
was published
Jul 26, 2024
In snapd versions prior to 2.62, when using AppArmor for enforcement of
sandbox permissions,...
Moderate
Unreviewed
CVE-2024-1724
was published
Jul 25, 2024
A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x....
Moderate
Unreviewed
CVE-2024-7105
was published
Jul 25, 2024
HMS Industrial Networks
Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by...
Moderate
Unreviewed
CVE-2024-6558
was published
Jul 25, 2024
In snapd versions prior to 2.62, snapd failed to properly check the
destination of symbolic links...
Moderate
Unreviewed
CVE-2024-29069
was published
Jul 25, 2024
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this...
Moderate
Unreviewed
CVE-2024-7106
was published
Jul 25, 2024
In snapd versions prior to 2.62, snapd failed to properly check the file
type when extracting a...
Moderate
Unreviewed
CVE-2024-29068
was published
Jul 25, 2024
There is a cross-site scripting vulnerability in the Secure
Access administrative console of...
Moderate
Unreviewed
CVE-2024-40873
was published
Jul 25, 2024
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is...
Moderate
Unreviewed
CVE-2024-28772
was published
Jul 25, 2024
A vulnerability, which was classified as critical, has been found in ForIP Tecnologia...
Moderate
Unreviewed
CVE-2024-7101
was published
Jul 25, 2024
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses...
Moderate
Unreviewed
CVE-2022-32759
was published
Jul 25, 2024
Craft CMS Allows TOTP Token To Stay Valid After Use
Moderate
CVE-2024-41800
was published
for
craftcms/cms
(Composer)
Jul 25, 2024
Vulnerability of serialisation/deserialisation mismatch in the iAware module. Impact: Successful...
Moderate
Unreviewed
CVE-2024-39673
was published
Jul 25, 2024
Plaintext vulnerability in the Gallery search module.
Impact: Successful exploitation of this...
Moderate
Unreviewed
CVE-2024-39674
was published
Jul 25, 2024
Privilege escalation vulnerability in the account synchronisation module.
Impact: Successful...
Moderate
Unreviewed
CVE-2024-39670
was published
Jul 25, 2024
ProTip!
Advisories are also available from the
GraphQL API