GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,991
Erlang
29
GitHub Actions
16
Go
1,779
Maven
5,000+
npm
3,544
NuGet
619
pip
3,134
Pub
10
RubyGems
838
Rust
793
Swift
34
Unreviewed advisories
All unreviewed
5,000+
243,117 advisories
Filter by severity
A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll...
Moderate
Unreviewed
CVE-2024-7117
was published
Jul 26, 2024
An issue was discovered by Elastic whereby Watcher search input logged the search query results...
Moderate
Unreviewed
CVE-2023-49921
was published
Jul 26, 2024
Stack-based buffer overflow vulnerability exists in orcparse.c of ORC versions prior to 0.4.39....
Unknown
Unreviewed
CVE-2024-40897
was published
Jul 26, 2024
A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online...
Moderate
Unreviewed
CVE-2024-7119
was published
Jul 26, 2024
A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management...
Moderate
Unreviewed
CVE-2024-7118
was published
Jul 26, 2024
During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was...
Unknown
Unreviewed
CVE-2024-6490
was published
Jul 26, 2024
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E,...
Moderate
Unreviewed
CVE-2024-7120
was published
Jul 26, 2024
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via...
Moderate
Unreviewed
CVE-2024-4447
was published
Jul 26, 2024
A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-7114
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7116
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7115
was published
Jul 26, 2024
Softaculous Webuzo contains a command injection vulnerability in the FTP management functionality...
High
Unreviewed
CVE-2024-24623
was published
Jul 26, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38103
was published
Jul 26, 2024
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the mac...
Unknown
Unreviewed
CVE-2024-41473
was published
Jul 26, 2024
The "reset password" login page accepted an HTML injection via URL parameters.
This has already...
Moderate
Unreviewed
CVE-2024-3938
was published
Jul 26, 2024
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the...
Unknown
Unreviewed
CVE-2024-41468
was published
Jul 26, 2024
Softaculous Webuzo contains a command injection in the password reset functionality. A remote,...
High
Unreviewed
CVE-2024-24622
was published
Jul 26, 2024
Softaculous Webuzo contains an authentication bypass vulnerability through the password reset...
Critical
Unreviewed
CVE-2024-24621
was published
Jul 26, 2024
BlastRADIUS also affects eduMFA
Moderate
GHSA-vhmj-5q9r-mm9g
was published
for
edumfa
(pip)
Jul 17, 2024
Cross Site Scripting vulnerability in TWCMS v.2.0.3 allows a remote attacker to execute arbitrary...
Moderate
Unreviewed
CVE-2024-37878
was published
Jun 12, 2024
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is...
Moderate
Unreviewed
CVE-2024-3164
was published
Apr 2, 2024
Undertow's url-encoded request path information can be broken on ajp-listener
High
CVE-2024-6162
was published
for
io.undertow:undertow-core
(Maven)
Jun 20, 2024
System->Maintenance-> Log Files in dotCMS dashboard is providing the username/password for...
Moderate
Unreviewed
CVE-2024-3165
was published
Apr 2, 2024
A vulnerability classified as problematic was found in Spina CMS 2.18.0. Affected by this...
Moderate
Unreviewed
CVE-2024-7106
was published
Jul 25, 2024
A CRLF injection vulnerability in E-Staff v5.1 allows attackers to insert Carriage Return (CR)...
Unknown
Unreviewed
CVE-2024-40324
was published
Jul 25, 2024
ProTip!
Advisories are also available from the
GraphQL API