GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
Cleartext Transmission of Sensitive Information, Inclusion of Functionality from Untrusted Control Sphere , and Download of Code Without Integrity Check in Eclipse hawkBit
High
CVE-2019-10240
was published
for
org.eclipse.hawkbit:hawkbit-autoconfigure
(Maven)
Apr 15, 2019
Unintended Require in larvitbase-api
High
CVE-2019-5479
was published
for
larvitbase-api
(npm)
Sep 11, 2019
High severity vulnerability that affects generator-jhipster
High
GHSA-mc84-xr9p-938r
was published
for
generator-jhipster
(npm)
Sep 23, 2019
Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport
High
CVE-2020-8128
was published
for
jsreport
(npm)
Apr 13, 2021
PHPMailer untrusted code may be run from an overridden address validator
High
CVE-2021-3603
was published
for
phpmailer/phpmailer
(Composer)
Jun 22, 2021
Embedded malware in ua-parser-js
High
GHSA-pjwm-rvh2-c87w
was published
for
ua-parser-js
(npm)
Oct 22, 2021
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an...
High
Unreviewed
CVE-2021-42133
was published
Dec 8, 2021
A vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that...
High
Unreviewed
CVE-2021-41841
was published
Feb 10, 2022
A local file inclusion in Hospital Patient Record Management System v1.0 allows attackers to...
High
Unreviewed
CVE-2022-24232
was published
Feb 25, 2022
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts...
High
Unreviewed
CVE-2022-25486
was published
Mar 16, 2022
CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts...
High
Unreviewed
CVE-2022-25485
was published
Mar 16, 2022
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and ...
High
Unreviewed
CVE-2004-0030
was published
Apr 29, 2022
PHP remote file inclusion vulnerabilities in include/footer.inc.php in (1) AllMyVisitors, (2)...
High
Unreviewed
CVE-2004-0285
was published
Apr 29, 2022
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a...
High
Unreviewed
CVE-2019-9829
was published
May 13, 2022
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by...
High
Unreviewed
CVE-2018-12120
was published
May 13, 2022
A vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 and below could...
High
Unreviewed
CVE-2017-14095
was published
May 13, 2022
Drupal Remote code execution
High
CVE-2017-6381
was published
for
drupal/core
(Composer)
May 13, 2022
MyBB Group MyBB contains a File Inclusion vulnerability in Admin panel (Tools and Maintenance ->...
High
Unreviewed
CVE-2018-1000502
was published
May 13, 2022
playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
High
Unreviewed
CVE-2018-18387
was published
May 13, 2022
Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS
High
CVE-2019-10248
was published
for
org.eclipse.vorto:org.eclipse.vorto.core
(Maven)
May 24, 2022
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
High
CVE-2021-20187
was published
for
moodle/moodle
(Composer)
May 24, 2022
IBM Maximo for Civil Infrastructure 7.6.2 includes executable functionality (such as a library)...
High
Unreviewed
CVE-2021-20443
was published
May 24, 2022
Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212...
High
Unreviewed
CVE-2021-30507
was published
May 24, 2022
Local file inclusion exists in Kaseya VSA before 9.5.6.
High
Unreviewed
CVE-2021-30121
was published
May 24, 2022
iDrive RemotePC before 7.6.48 on Windows allows privilege escalation. A local and low-privileged...
High
Unreviewed
CVE-2021-34692
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API