GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
220 advisories
Filter by severity
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
Critical
Unreviewed
CVE-2022-45550
was published
Dec 7, 2022
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to...
Critical
Unreviewed
CVE-2022-3643
was published
Dec 7, 2022
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This...
Critical
Unreviewed
CVE-2022-4257
was published
Dec 1, 2022
Code injection in quarkus dev ui config editor
Critical
CVE-2022-4116
was published
for
io.quarkus:quarkus-vertx-http-deployment
(Maven)
Nov 22, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-menu-ui
Critical
CVE-2022-41934
was published
for
org.xwiki.platform:xwiki-platform-menu-ui
(Maven)
Nov 21, 2022
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue...
Critical
Unreviewed
CVE-2022-4011
was published
Nov 16, 2022
A vulnerability has been found in Activity Log Plugin and classified as critical. This...
Critical
Unreviewed
CVE-2022-3941
was published
Nov 11, 2022
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
Critical
Unreviewed
CVE-2022-27858
was published
Nov 9, 2022
@keystone-6/core's NODE_ENV defaults to development with esbuild
Critical
CVE-2022-39382
was published
for
@keystone-6/core
(npm)
Nov 3, 2022
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper...
Critical
Unreviewed
CVE-2021-38395
was published
Oct 28, 2022
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in...
Critical
Unreviewed
CVE-2020-27602
was published
Sep 30, 2022
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to...
Critical
Unreviewed
CVE-2022-3236
was published
Sep 25, 2022
Valine code injection vulnerability
Critical
CVE-2022-38545
was published
for
valine
(npm)
Sep 20, 2022
cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearch
Critical
CVE-2022-36084
was published
for
cruddl
(npm)
Sep 16, 2022
Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can...
Critical
Unreviewed
CVE-2022-34773
was published
Aug 23, 2022
Remote code execution in Apache Flume
Critical
CVE-2022-34916
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Aug 22, 2022
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows...
Critical
Unreviewed
CVE-2022-34294
was published
Aug 16, 2022
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A...
Critical
Unreviewed
CVE-2022-31657
was published
Aug 6, 2022
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as...
Critical
Unreviewed
CVE-2016-15004
was published
Jul 24, 2022
Shescape vulnerable to insufficient escaping of whitespace
Critical
CVE-2022-31180
was published
for
shescape
(npm)
Jul 15, 2022
Webswing before 22.1.3 allows X-Forwarded-For header injection. The client IP address is...
Critical
Unreviewed
CVE-2022-34914
was published
Jul 9, 2022
Code injection in Apache Commons Configuration
Critical
CVE-2022-33980
was published
for
org.apache.commons:commons-configuration2
(Maven)
Jul 7, 2022
There is an object injection vulnerability in swfupload plugin for wordpress.
Critical
Unreviewed
CVE-2013-4144
was published
Jul 1, 2022
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be...
Critical
Unreviewed
CVE-2022-32534
was published
Jun 24, 2022
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local...
Critical
Unreviewed
CVE-2022-32269
was published
Jun 4, 2022
ProTip!
Advisories are also available from the
GraphQL API