GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,067
Erlang
29
GitHub Actions
19
Go
1,891
Maven
5,000+
npm
3,624
NuGet
638
pip
3,235
Pub
10
RubyGems
857
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
3,767 advisories
Filter by severity
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url...
High
Unreviewed
CVE-2024-44724
was published
Sep 9, 2024
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode...
High
Unreviewed
CVE-2024-8478
was published
Sep 10, 2024
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to...
High
Unreviewed
CVE-2024-8268
was published
Sep 10, 2024
An unauthenticated remote attacker can run malicious c# code included in curve files and execute...
Critical
Unreviewed
CVE-2024-6596
was published
Sep 10, 2024
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options...
Low
Unreviewed
CVE-2024-8258
was published
Sep 10, 2024
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
Critical
Unreviewed
CVE-2024-44411
was published
Sep 9, 2024
Azure CycleCloud Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-43469
was published
Sep 10, 2024
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
Critical
Unreviewed
CVE-2024-44410
was published
Sep 9, 2024
The Bit File Manager plugin for WordPress is vulnerable to Remote Code Execution in versions 6.0...
High
Unreviewed
CVE-2024-7627
was published
Sep 5, 2024
Apache Airflow vulnerable to OS Command Injection via example DAGs
High
CVE-2022-40127
was published
for
apache-airflow
(pip)
Nov 14, 2022
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php...
Critical
Unreviewed
CVE-2023-46010
was published
Oct 25, 2023
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a...
High
Unreviewed
CVE-2023-43352
was published
Oct 27, 2023
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary...
Critical
Unreviewed
CVE-2023-46509
was published
Oct 27, 2023
An issue in GetSimpleCMS v.3.4.0a allows a remote attacker to execute arbitrary code via a...
Critical
Unreviewed
CVE-2023-46042
was published
Oct 19, 2023
free5GC AMF denial of service vulnerability
High
CVE-2023-49391
was published
for
github.com/free5gc/amf
(Go)
Dec 22, 2023
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands,...
Critical
Unreviewed
CVE-2023-30131
was published
Oct 19, 2023
Cobbler before 3.3.0 allows log poisoning
High
CVE-2021-40323
was published
for
cobbler
(pip)
Oct 5, 2021
remote code execution via git repo provider
Critical
CVE-2021-39159
was published
for
binderhub
(pip)
Aug 30, 2021
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers...
Critical
Unreviewed
CVE-2024-44466
was published
Sep 11, 2024
Remote Code Execution in create_conda_env function in lollms
Moderate
CVE-2024-3121
was published
for
lollms
(pip)
Jun 24, 2024
Code injection in Danijar Definitions
High
CVE-2018-20325
was published
for
definitions
(pip)
Dec 26, 2018
The The Simple Spoiler plugin for WordPress is vulnerable to arbitrary shortcode execution in...
High
Unreviewed
CVE-2024-8479
was published
Sep 16, 2024
The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-8271
was published
Sep 16, 2024
A vulnerability has been found in composiohq composio up to 0.5.6 and classified as critical....
Moderate
Unreviewed
CVE-2024-8864
was published
Sep 16, 2024
A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7....
Moderate
Unreviewed
CVE-2024-8880
was published
Sep 16, 2024
ProTip!
Advisories are also available from the
GraphQL API