GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
27,895 advisories
Filter by severity
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24329
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24328
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24331
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24327
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24330
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24332
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24325
was published
Jan 30, 2024
TOTOLINK A8000RU v7.1cu.643_B20200521 was discovered to contain a hardcoded password for root...
Critical
Unreviewed
CVE-2024-24324
was published
Jan 30, 2024
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2024-24326
was published
Jan 30, 2024
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability...
Critical
Unreviewed
CVE-2023-6943
was published
Jan 30, 2024
DuckDB <=0.9.2 and DuckDB extension-template <=0.9.2 are vulnerable to malicious extension...
Critical
Unreviewed
CVE-2024-22682
was published
Jan 30, 2024
Sourcecodester School Task Manager App 1.0 allows SQL Injection via the 'task' parameter.
Critical
Unreviewed
CVE-2024-24141
was published
Jan 29, 2024
DoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.
Critical
Unreviewed
CVE-2023-51840
was published
Jan 29, 2024
Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03...
Critical
Unreviewed
CVE-2024-1015
was published
Jan 29, 2024
An issue in Kap for macOS version 3.6.0 and before, allows remote attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-23740
was published
Jan 28, 2024
An issue in Discord for macOS version 0.0.291 and before, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-23739
was published
Jan 28, 2024
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary...
Critical
Unreviewed
CVE-2024-23741
was published
Jan 28, 2024
An issue in Notion for macOS version 3.1.0 and before, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-23743
was published
Jan 28, 2024
An issue in Postman version 10.22 and before on macOS allows a remote attacker to execute...
Critical
Unreviewed
CVE-2024-23738
was published
Jan 28, 2024
An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-23742
was published
Jan 28, 2024
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-22862
was published
Jan 27, 2024
Integer overflow vulnerability in FFmpeg before n6.1, allows remote attackers to execute...
Critical
Unreviewed
CVE-2024-22860
was published
Jan 27, 2024
UTF32Encoding.cpp in POCO has a Poco::UTF32Encoding integer overflow and resultant stack buffer...
Critical
Unreviewed
CVE-2023-52389
was published
Jan 27, 2024
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products...
Critical
Unreviewed
CVE-2024-20253
was published
Jan 26, 2024
An issue was discovered in OpenNDS before 10.1.3. It fails to sanitize the status path script...
Critical
Unreviewed
CVE-2023-38323
was published
Jan 26, 2024
ProTip!
Advisories are also available from the
GraphQL API