GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
226 advisories
Filter by severity
A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the...
Critical
Unreviewed
CVE-2022-4768
was published
Dec 28, 2022
Apache Karaf vulnerable to potential code injection
Critical
CVE-2022-40145
was published
for
org.apache.karaf:apache-karaf
(Maven)
Dec 21, 2022
Softr v2.0 was discovered to be vulnerable to HTML injection via the Name field of the Account page.
Critical
Unreviewed
CVE-2022-40434
was published
Dec 20, 2022
FurqanSoftware/node-whois vulnerable to Prototype Pollution
Critical
CVE-2020-36618
was published
for
whois
(npm)
Dec 19, 2022
npm package rfc6902 vulnerable to Prototype Pollution
Critical
CVE-2021-4245
was published
for
rfc6902
(npm)
Dec 15, 2022
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background...
Critical
Unreviewed
CVE-2022-4170
was published
Dec 9, 2022
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
Critical
Unreviewed
CVE-2022-45550
was published
Dec 7, 2022
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to...
Critical
Unreviewed
CVE-2022-3643
was published
Dec 7, 2022
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This...
Critical
Unreviewed
CVE-2022-4257
was published
Dec 1, 2022
Code injection in quarkus dev ui config editor
Critical
CVE-2022-4116
was published
for
io.quarkus:quarkus-vertx-http-deployment
(Maven)
Nov 22, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-menu-ui
Critical
CVE-2022-41934
was published
for
org.xwiki.platform:xwiki-platform-menu-ui
(Maven)
Nov 21, 2022
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue...
Critical
Unreviewed
CVE-2022-4011
was published
Nov 16, 2022
A vulnerability has been found in Activity Log Plugin and classified as critical. This...
Critical
Unreviewed
CVE-2022-3941
was published
Nov 11, 2022
CSV Injection vulnerability in Activity Log Team Activity Log <= 2.8.3 on WordPress.
Critical
Unreviewed
CVE-2022-27858
was published
Nov 9, 2022
@keystone-6/core's NODE_ENV defaults to development with esbuild
Critical
CVE-2022-39382
was published
for
@keystone-6/core
(npm)
Nov 3, 2022
Honeywell Experion PKS C200, C200E, C300, and ACE controllers are vulnerable to improper...
Critical
Unreviewed
CVE-2021-38395
was published
Oct 28, 2022
BigBlueButton before 2.2.7 does not have a protection mechanism for separator injection in...
Critical
Unreviewed
CVE-2020-27602
was published
Sep 30, 2022
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to...
Critical
Unreviewed
CVE-2022-3236
was published
Sep 25, 2022
Valine code injection vulnerability
Critical
CVE-2022-38545
was published
for
valine
(npm)
Sep 20, 2022
cruddl vulnerable to ArangoDB Query Language (AQL) injection through flexSearch
Critical
CVE-2022-36084
was published
for
cruddl
(npm)
Sep 16, 2022
Tabit - HTTP Method manipulation. https://bridge.tabit.cloud/configuration/addresses-query - can...
Critical
Unreviewed
CVE-2022-34773
was published
Aug 23, 2022
Remote code execution in Apache Flume
Critical
CVE-2022-34916
was published
for
org.apache.flume.flume-ng-sources:flume-jms-source
(Maven)
Aug 22, 2022
totd 1.5.3 uses a fixed UDP source port in upstream queries sent to DNS resolvers. This allows...
Critical
Unreviewed
CVE-2022-34294
was published
Aug 16, 2022
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A...
Critical
Unreviewed
CVE-2022-31657
was published
Aug 6, 2022
A vulnerability was found in InfiniteWP Client Plugin 1.5.1.3/1.6.0. It has been declared as...
Critical
Unreviewed
CVE-2016-15004
was published
Jul 24, 2022
ProTip!
Advisories are also available from the
GraphQL API