GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
27,895 advisories
Filter by severity
TOTOLINK A3700R_V9.1.2u.6165_20211012 has a stack overflow vulnerability via setParentalRules
Critical
Unreviewed
CVE-2024-22662
was published
Jan 23, 2024
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
Critical
Unreviewed
CVE-2024-22663
was published
Jan 23, 2024
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a stack overflow vulnerability via setLanguageCfg
Critical
Unreviewed
CVE-2024-22660
was published
Jan 23, 2024
MyQ Print Server before 8.2 patch 43 allows Unauthenticated Remote Code Execution.
Critical
Unreviewed
CVE-2024-22076
was published
Jan 23, 2024
An issue was discovered in Contiki-NG tinyDTLS through 2018-08-30. One incorrect handshake could...
Critical
Unreviewed
CVE-2021-42141
was published
Jan 23, 2024
SQL Injection vulnerability in Quest Analytics LLC IQCRM v.2023.9.5 allows a remote attacker to...
Critical
Unreviewed
CVE-2023-48118
was published
Jan 22, 2024
Authentication bypass in Fortra's GoAnywhere MFT prior to 7.4.1 allows an unauthorized user to...
Critical
Unreviewed
CVE-2024-0204
was published
Jan 22, 2024
darkhttpd before 1.15 uses strcmp (which is not constant time) to verify authentication, which...
Critical
Unreviewed
CVE-2024-23771
was published
Jan 22, 2024
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou...
Critical
Unreviewed
CVE-2023-51927
was published
Jan 20, 2024
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a...
Critical
Unreviewed
CVE-2023-51906
was published
Jan 20, 2024
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2023-51892
was published
Jan 20, 2024
File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload...
Critical
Unreviewed
CVE-2021-31314
was published
Jan 20, 2024
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action...
Critical
Unreviewed
CVE-2023-51925
was published
Jan 20, 2024
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of...
Critical
Unreviewed
CVE-2023-51924
was published
Jan 20, 2024
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action...
Critical
Unreviewed
CVE-2023-51928
was published
Jan 20, 2024
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-50694
was published
Jan 19, 2024
An issue in dom96 Jester v.0.6.0 and before allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-50693
was published
Jan 19, 2024
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote...
Critical
Unreviewed
CVE-2023-51947
was published
Jan 19, 2024
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to...
Critical
Unreviewed
CVE-2023-27168
was published
Jan 19, 2024
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules...
Critical
Unreviewed
CVE-2023-50028
was published
Jan 19, 2024
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL...
Critical
Unreviewed
CVE-2023-50030
was published
Jan 19, 2024
SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via...
Critical
Unreviewed
CVE-2023-43985
was published
Jan 19, 2024
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The...
Critical
Unreviewed
CVE-2023-46351
was published
Jan 19, 2024
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via...
Critical
Unreviewed
CVE-2024-0705
was published
Jan 19, 2024
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to...
Critical
Unreviewed
CVE-2023-5716
was published
Jan 19, 2024
ProTip!
Advisories are also available from the
GraphQL API