GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,667
Maven
5,000+
npm
4,295
NuGet
760
pip
4,073
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
27,518 advisories
Filter by severity
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta...
Critical
Unreviewed
CVE-2023-3265
was published
Aug 14, 2023
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to...
Critical
Unreviewed
CVE-2023-3264
was published
Aug 14, 2023
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to...
Critical
Unreviewed
CVE-2023-3259
was published
Aug 14, 2023
Vulnerability of configuration defects in the media module of certain products.. Successful...
Critical
Unreviewed
CVE-2023-39385
was published
Aug 13, 2023
Vulnerability of defects introduced in the design process in the Multi-Device Task Center....
Critical
Unreviewed
CVE-2021-46895
was published
Aug 13, 2023
Vulnerability of out-of-bounds parameter read/write in the Wi-Fi module. Successful exploitation...
Critical
Unreviewed
CVE-2023-39405
was published
Aug 13, 2023
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and...
Critical
Unreviewed
CVE-2023-3452
was published
Aug 12, 2023
An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain,...
Critical
Unreviewed
CVE-2021-27523
was published
Aug 11, 2023
File Upload vulnerability in bloofoxCMS version 0.5.2.1, allows remote attackers to execute...
Critical
Unreviewed
CVE-2020-36082
was published
Aug 11, 2023
SQL Injection vulnerability in oretnom23 School Faculty Scheduling System version 1.0, allows...
Critical
Unreviewed
CVE-2020-36034
was published
Aug 11, 2023
Directory Traversal vulnerability in delete function in admin.api.TemplateController in ZrLog...
Critical
Unreviewed
CVE-2020-27514
was published
Aug 11, 2023
An issue was discovered in FoldingAtHome Client Advanced Control GUI before commit...
Critical
Unreviewed
CVE-2020-27544
was published
Aug 11, 2023
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian...
Critical
Unreviewed
CVE-2023-40254
was published
Aug 11, 2023
EmpowerID before 7.205.0.1 allows an attacker to bypass an MFA (multi factor authentication)...
Critical
Unreviewed
CVE-2023-40260
was published
Aug 11, 2023
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0,...
Critical
Unreviewed
CVE-2023-40253
was published
Aug 11, 2023
A vulnerability was discovered in Veritas NetBackup Snapshot Manager before 10.2.0.1 that allowed...
Critical
Unreviewed
CVE-2023-40256
was published
Aug 11, 2023
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow...
Critical
Unreviewed
CVE-2023-27515
was published
Aug 11, 2023
Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3...
Critical
Unreviewed
CVE-2022-29887
was published
Aug 11, 2023
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
Critical
Unreviewed
CVE-2023-39806
was published
Aug 10, 2023
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at...
Critical
Unreviewed
CVE-2023-39805
was published
Aug 10, 2023
There is a SQL injection (SQLi) vulnerability in the "column" parameter of index.php in...
Critical
Unreviewed
CVE-2023-36311
was published
Aug 10, 2023
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute...
Critical
Unreviewed
CVE-2023-39776
was published
Aug 10, 2023
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
Critical
Unreviewed
CVE-2023-37734
was published
Aug 10, 2023
A remote code execution vulnerability in the webview component of OPPO Store app.
Critical
Unreviewed
CVE-2023-26311
was published
Aug 10, 2023
A remote code execution vulnerability in the webview component of OnePlus Mall app.
Critical
Unreviewed
CVE-2023-26309
was published
Aug 10, 2023
ProTip!
Advisories are also available from the
GraphQL API