GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,653
Erlang
29
GitHub Actions
16
Go
1,706
Maven
4,938
npm
3,471
NuGet
603
pip
2,985
Pub
10
RubyGems
826
Rust
772
Swift
34
Unreviewed advisories
All unreviewed
5,000+
92,715 advisories
Filter by severity
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and...
High
Unreviewed
CVE-2024-4835
was published
May 23, 2024
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is...
High
Unreviewed
CVE-2024-2038
was published
May 23, 2024
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds...
High
Unreviewed
CVE-2024-30280
was published
May 23, 2024
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds...
High
Unreviewed
CVE-2024-30279
was published
May 23, 2024
The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up...
High
Unreviewed
CVE-2024-4347
was published
May 23, 2024
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
High
Unreviewed
CVE-2024-4662
was published
May 23, 2024
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is...
High
Unreviewed
CVE-2024-4978
was published
May 23, 2024
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local...
High
Unreviewed
CVE-2024-29853
was published
May 23, 2024
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
High
Unreviewed
CVE-2024-29850
was published
May 23, 2024
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise...
High
Unreviewed
CVE-2024-29851
was published
May 23, 2024
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-4454
was published
May 22, 2024
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-4453
was published
May 22, 2024
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2023-51636
was published
May 22, 2024
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated...
High
Unreviewed
CVE-2024-27264
was published
May 22, 2024
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically...
High
Unreviewed
CVE-2024-4267
was published
May 22, 2024
Silverstripe SiteTree Creation Permission Vulnerability
High
GHSA-3mm9-2p44-rw39
was published
for
silverstripe/cms
(Composer)
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2023-20239
was published
May 22, 2024
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their...
High
Unreviewed
CVE-2024-36077
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2024-20360
was published
May 22, 2024
Ghost allows CSV Injection during member CSV export
High
CVE-2024-34448
was published
for
@tryghost/members-csv
(npm)
May 22, 2024
gix traversal outside working tree enables arbitrary code execution
High
CVE-2024-35186
was published
for
gitoxide
(Rust)
May 22, 2024
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2024-4262
was published
May 22, 2024
The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all...
High
Unreviewed
CVE-2024-5031
was published
May 22, 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin...
High
Unreviewed
CVE-2024-4157
was published
May 22, 2024
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive...
High
Unreviewed
CVE-2024-2088
was published
May 22, 2024
ProTip!
Advisories are also available from the
GraphQL API