GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,064
Maven
5,000+
npm
3,744
NuGet
668
pip
3,424
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
24,106 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP...
Critical
Unreviewed
CVE-2024-56278
was published
Jan 7, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56284
was published
Jan 7, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56290
was published
Jan 7, 2025
Deserialization of Untrusted Data vulnerability in Amento Tech Pvt ltd WPGuppy allows Object...
Critical
Unreviewed
CVE-2024-49222
was published
Jan 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-49649
was published
Jan 7, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing...
Critical
Unreviewed
CVE-2024-43243
was published
Jan 7, 2025
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege...
Critical
Unreviewed
CVE-2024-12470
was published
Jan 7, 2025
The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a...
Critical
Unreviewed
CVE-2024-8855
was published
Jan 7, 2025
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing...
Critical
Unreviewed
CVE-2024-12252
was published
Jan 7, 2025
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all...
Critical
Unreviewed
CVE-2024-12264
was published
Jan 7, 2025
The Themes Coder – Create Android & iOS Apps For Your Woocommerce Site plugin for WordPress is...
Critical
Unreviewed
CVE-2024-12402
was published
Jan 7, 2025
Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.
Critical
Unreviewed
CVE-2024-55529
was published
Jan 6, 2025
An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software...
Critical
Unreviewed
CVE-2024-46622
was published
Jan 6, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which attackers can use to...
Critical
Unreviewed
CVE-2024-5594
was published
Jan 6, 2025
In wlan STA FW, there is a possible out of bounds write due to improper input validation. This...
Critical
Unreviewed
CVE-2024-20148
was published
Jan 6, 2025
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and...
Critical
Unreviewed
CVE-2024-12583
was published
Jan 4, 2025
In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32...
Critical
Unreviewed
CVE-2025-22376
was published
Jan 4, 2025
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate...
Critical
Unreviewed
CVE-2024-55507
was published
Jan 3, 2025
An arbitrary file upload vulnerability in the component /adminUser/updateImg of WukongCRM-11.0...
Critical
Unreviewed
CVE-2024-55078
was published
Jan 3, 2025
Moxa’s cellular routers, secure routers, and network security appliances are affected by a...
Critical
Unreviewed
CVE-2024-9140
was published
Jan 3, 2025
In cc_SendCcImsInfoIndMsg of cc_MmConManagement.c, there is a possible out of bounds write due to...
Critical
Unreviewed
CVE-2024-53842
was published
Jan 3, 2025
iTerm2 3.5.6 through 3.5.10 before 3.5.11 sometimes allows remote attackers to obtain sensitive...
Critical
Unreviewed
CVE-2025-22275
was published
Jan 3, 2025
path-sanitizer allows bypassing the existing filters to achieve path-traversal vulnerability
Critical
CVE-2024-56198
was published
for
path-sanitizer
(npm)
Jan 2, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Webdeclic WPMasterToolKit allows...
Critical
Unreviewed
CVE-2024-56249
was published
Jan 2, 2025
ProTip!
Advisories are also available from the
GraphQL API