GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
23 advisories
Filter by severity
Exposed Dangerous Method or Function vulnerability in Drupal Swift Mailer allows Resource...
Critical
Unreviewed
CVE-2024-13242
was published
Jan 9, 2025
Voltronic Power ViewPower MonitorConsole Exposed Dangerous Method Remote Code Execution...
Critical
Unreviewed
CVE-2023-51575
was published
May 3, 2024
Voltronic Power ViewPower MacMonitorConsole Exposed Dangerous Method Remote Code Execution...
Critical
Unreviewed
CVE-2023-51581
was published
May 3, 2024
Voltronic Power ViewPower updateManagerPassword Exposed Dangerous Method Authentication Bypass...
Critical
Unreviewed
CVE-2023-51574
was published
May 3, 2024
Voltronic Power ViewPower UpsScheduler Exposed Dangerous Method Remote Code Execution...
Critical
Unreviewed
CVE-2023-51583
was published
May 3, 2024
Voltronic Power ViewPower LinuxMonitorConsole Exposed Dangerous Method Remote Code Execution...
Critical
Unreviewed
CVE-2023-51582
was published
May 3, 2024
D-Link D-View coreservice_action_script Exposed Dangerous Function Remote Code Execution...
Critical
Unreviewed
CVE-2023-44414
was published
May 3, 2024
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This...
Critical
Unreviewed
CVE-2023-40501
was published
May 3, 2024
LG Simple Editor copyContent Exposed Dangerous Function Remote Code Execution Vulnerability. This...
Critical
Unreviewed
CVE-2023-40500
was published
May 3, 2024
Voltronic Power ViewPower Pro updateManagerPassword Exposed Dangerous Function Authentication...
Critical
Unreviewed
CVE-2023-51573
was published
Apr 2, 2024
LangChain Experimental vulnerable to arbitrary code execution
Critical
CVE-2024-27444
was published
for
langchain-experimental
(pip)
Feb 26, 2024
An attacker could potentially exploit this vulnerability, leading to the ability to modify files...
Critical
Unreviewed
CVE-2023-5389
was published
Jan 30, 2024
Duplicate Advisory: Privilege escalation in sap/cloud-security-client-go
Critical
GHSA-92cg-ghq6-9587
was published
for
github.com/sap/cloud-security-client-go
(Go)
Dec 12, 2023
•
withdrawn
Duplicate Advisory: Privilege escalation in sap-xssec
Critical
GHSA-p99h-pfg6-qrfg
was published
for
sap-xssec
(pip)
Dec 12, 2023
•
withdrawn
Escalation of privileges in @sap/xssec
Critical
CVE-2023-49583
was published
for
@sap/xssec
(npm)
Dec 12, 2023
Duplicate Advisory: Improper JWT Signature Validation in SAP Security Services Library
Critical
GHSA-gcgw-q47m-prvj
was published
for
com.sap.cloud.security.xsuaa:spring-xsuaa
(Maven)
Dec 12, 2023
•
withdrawn
In Delta Electronics InfraSuite Device Master v.1.0.7, a vulnerability exists that allows an...
Critical
Unreviewed
CVE-2023-39226
was published
Dec 1, 2023
When user authentication is not enabled the shell can execute commands with the highest...
Critical
Unreviewed
CVE-2023-40151
was published
Nov 21, 2023
EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
Critical
Unreviewed
CVE-2023-42494
was published
Oct 25, 2023
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to...
Critical
Unreviewed
CVE-2023-3656
was published
Oct 3, 2023
?The affected product does not perform an authentication check and performs some dangerous...
Critical
Unreviewed
CVE-2023-40150
was published
Sep 11, 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of...
Critical
Unreviewed
CVE-2022-36983
was published
Mar 29, 2023
Cobbler has Exposed Dangerous Method or Function
Critical
CVE-2018-10931
was published
for
cobbler
(pip)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API