GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
27,895 advisories
Filter by severity
Heap-based buffer overflow vulnerability exists in HOME SPOT CUBE2 V102 and earlier. By...
Critical
Unreviewed
CVE-2024-23978
was published
Feb 2, 2024
Aprktool before 2.9.3 on Windows allows ../ and /.. directory traversal.
Critical
Unreviewed
CVE-2024-24482
was published
Feb 2, 2024
Miro Desktop 0.8.18 on macOS allows Electron code injection.
Critical
Unreviewed
CVE-2024-23746
was published
Feb 2, 2024
IBM Operational Decision Manager 8.10.3, 8.10.4, 8.10.5.1, 8.11, 8.11.0.1, and 8.12.0.1 could...
Critical
Unreviewed
CVE-2024-22320
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to be configured with default root credentials.
Critical
Unreviewed
CVE-2024-22902
was published
Feb 2, 2024
Zoho ManageEngine ADAudit Plus through 7250 is vulnerable to SQL Injection in the report export...
Critical
Unreviewed
CVE-2023-48792
was published
Feb 2, 2024
Vinchin Backup & Recovery v7.2 was discovered to use default MYSQL credentials.
Critical
Unreviewed
CVE-2024-22901
was published
Feb 2, 2024
Zoho ManageEngine ADAudit Plus through 7250 allows SQL Injection in the aggregate report feature.
Critical
Unreviewed
CVE-2023-48793
was published
Feb 2, 2024
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded...
Critical
Unreviewed
CVE-2024-21764
was published
Feb 2, 2024
The MachineSense application programmable interface (API) is improperly protected and can be...
Critical
Unreviewed
CVE-2023-49617
was published
Feb 2, 2024
Multiple MachineSense devices have credentials unable to be changed by the user or...
Critical
Unreviewed
CVE-2023-46706
was published
Feb 2, 2024
Gessler GmbH WEB-MASTER has a restoration account that uses weak hard coded credentials and if...
Critical
Unreviewed
CVE-2024-1039
was published
Feb 2, 2024
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number...
Critical
Unreviewed
CVE-2023-4472
was published
Feb 2, 2024
Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep...
Critical
Unreviewed
CVE-2023-5841
was published
Feb 1, 2024
An issue in Fronius Datalogger Web v.2.0.5-4, allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2023-37621
was published
Feb 1, 2024
SQL injection vulnerability in Enterprise Architect 16.0.1605 32-bit allows attackers to run...
Critical
Unreviewed
CVE-2022-47072
was published
Jan 31, 2024
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a...
Critical
Unreviewed
CVE-2024-21917
was published
Jan 31, 2024
SSL connections to NOVELL and Synology LDAP server are vulnerable to a man-in-the-middle attack...
Critical
Unreviewed
CVE-2023-50356
was published
Jan 31, 2024
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can...
Critical
Unreviewed
CVE-2024-23745
was published
Jan 31, 2024
An issue in the permission and access control components within ROS2 Foxy Fitzroy ROS_VERSION=2...
Critical
Unreviewed
CVE-2023-51198
was published
Jan 31, 2024
OS command injection vulnerability in command processing or system call componentsROS2 (Robot...
Critical
Unreviewed
CVE-2023-51202
was published
Jan 31, 2024
Insecure deserialization in ROS2 Foxy Fitzroy ROS_VERSION=2 and ROS_PYTHON_VERSION=3 allows...
Critical
Unreviewed
CVE-2023-51204
was published
Jan 31, 2024
An issue discovered in shell command execution in ROS2 (Robot Operating System 2) Foxy Fitzroy,...
Critical
Unreviewed
CVE-2023-51197
was published
Jan 31, 2024
An attacker could potentially exploit this vulnerability, leading to the ability to modify files...
Critical
Unreviewed
CVE-2023-5389
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24333
was published
Jan 30, 2024
ProTip!
Advisories are also available from the
GraphQL API