GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
A file disclosure vulnerability in Palo Alto Networks PAN-OS software enables an authenticated...
Moderate
Unreviewed
CVE-2023-0008
was published
May 10, 2023
Moodle External Control of File Name or Path vulnerability
Moderate
CVE-2023-30943
was published
for
moodle/moodle
(Composer)
May 2, 2023
A vulnerability has been found in SourceCodester Student Study Center Desk Management System 1.0...
Moderate
Unreviewed
CVE-2023-2152
was published
Apr 18, 2023
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an...
Moderate
Unreviewed
CVE-2023-0003
was published
Feb 8, 2023
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code...
Moderate
Unreviewed
CVE-2022-3032
was published
Dec 22, 2022
In multiple locations of NfcService.java, there is a possible disclosure of NFC tags due to a...
Moderate
Unreviewed
CVE-2022-20199
was published
Dec 20, 2022
ILIAS before 7.16 allows External Control of File Name or Path.
Moderate
Unreviewed
CVE-2022-45918
was published
Dec 7, 2022
The WordPress Infinite Scroll – Ajax Load More plugin for Wordpress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2022-2943
was published
Sep 7, 2022
The Export All URLs WordPress plugin before 4.4 does not validate the path of the file to be...
Moderate
Unreviewed
CVE-2022-2638
was published
Aug 29, 2022
An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of...
Moderate
Unreviewed
CVE-2022-32761
was published
Aug 23, 2022
An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6...
Moderate
Unreviewed
CVE-2022-28710
was published
Aug 23, 2022
A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50....
Moderate
Unreviewed
CVE-2015-10003
was published
Jul 18, 2022
Honeywell Alerton Compass Software 1.6.5 allows unauthenticated configuration changes from remote...
Moderate
Unreviewed
CVE-2022-30245
was published
Jul 16, 2022
Externally Controlled Reference to a Resource in Another Sphere in ruby-mysql
Moderate
CVE-2021-3779
was published
for
ruby-mysql
(RubyGems)
Jun 29, 2022
An arbitrary file deletion vulnerability exists within Maccms10.
Moderate
Unreviewed
CVE-2020-21363
was published
May 24, 2022
A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to...
Moderate
Unreviewed
CVE-2020-23171
was published
May 24, 2022
In scheduleTimeoutLocked of NotificationRecord.java, there is a possible disclosure of a...
Moderate
Unreviewed
CVE-2021-0599
was published
May 24, 2022
A malicious website that causes an HTTP Authentication dialog to be spawned could trick the built...
Moderate
Unreviewed
CVE-2021-29965
was published
May 24, 2022
A frame-injection issue in the online help in Redwood Report2Web 4.3.4.5 allows remote attackers...
Moderate
Unreviewed
CVE-2021-26711
was published
May 24, 2022
In AccountManager, there is a possible bypass of a permissions check due to a confused deputy....
Moderate
Unreviewed
CVE-2020-0338
was published
May 24, 2022
In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy....
Moderate
Unreviewed
CVE-2020-0337
was published
May 24, 2022
phpBB Server-Side Request Forgery Vulnerability
Moderate
CVE-2020-8226
was published
for
phpbb/phpbb
(Composer)
May 24, 2022
ingress-nginx component for Kubernetes allows file overwrite
Moderate
CVE-2020-8553
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2022
Information Disclosure is possible on WAGO Series PFC100 and PFC200 devices before FW12 due to...
Moderate
Unreviewed
CVE-2019-18202
was published
May 24, 2022
Shopware XXE Vulnerability
Moderate
CVE-2017-18357
was published
for
shopware/shopware
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API