GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
93,901 advisories
Filter by severity
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00...
High
Unreviewed
CVE-2024-4229
was published
Dec 19, 2024
The The Download Manager plugin for WordPress is vulnerable to arbitrary shortcode execution in...
High
Unreviewed
CVE-2024-11740
was published
Dec 19, 2024
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command (...
High
Unreviewed
CVE-2024-51532
was published
Dec 19, 2024
IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate...
High
Unreviewed
CVE-2024-35141
was published
Dec 19, 2024
An insecure library loading vulnerability has been reported to affect QVPN Device Client. If...
High
Unreviewed
CVE-2022-27595
was published
Dec 19, 2024
A cross-site scripting (XSS) vulnerability has been reported to affect several QNAP operating...
High
Unreviewed
CVE-2023-23354
was published
Dec 19, 2024
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205...
High
Unreviewed
CVE-2022-44513
was published
Dec 19, 2024
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205...
High
Unreviewed
CVE-2022-44512
was published
Dec 19, 2024
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205...
High
Unreviewed
CVE-2022-44518
was published
Dec 19, 2024
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205...
High
Unreviewed
CVE-2022-44520
was published
Dec 19, 2024
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205...
High
Unreviewed
CVE-2022-44514
was published
Dec 19, 2024
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates)...
High
Unreviewed
CVE-2024-55506
was published
Dec 19, 2024
A library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work...
High
Unreviewed
CVE-2024-41145
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially...
High
Unreviewed
CVE-2024-39804
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted...
High
Unreviewed
CVE-2024-43106
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially...
High
Unreviewed
CVE-2024-41159
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially...
High
Unreviewed
CVE-2024-42220
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094...
High
Unreviewed
CVE-2024-42004
was published
Dec 19, 2024
A library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted...
High
Unreviewed
CVE-2024-41165
was published
Dec 19, 2024
A library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of...
High
Unreviewed
CVE-2024-41138
was published
Dec 19, 2024
Keyfactor Command before 12.5.0 has Incorrect Access Control: access tokens are over permissioned...
High
Unreviewed
CVE-2024-49202
was published
Dec 18, 2024
Missing Authorization vulnerability in VibeThemes WPLMS allows Accessing Functionality Not...
High
Unreviewed
CVE-2024-56048
was published
Dec 18, 2024
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue...
High
Unreviewed
CVE-2024-56055
was published
Dec 18, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-56053
was published
Dec 18, 2024
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue...
High
Unreviewed
CVE-2024-56049
was published
Dec 18, 2024
ProTip!
Advisories are also available from the
GraphQL API