GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,840
Erlang
36
GitHub Actions
33
Go
2,464
Maven
5,000+
npm
4,082
NuGet
723
pip
3,880
Pub
12
RubyGems
943
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,665 advisories
Filter by severity
Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0...
Critical
Unreviewed
CVE-2022-42493
was published
Jan 27, 2023
Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0...
Critical
Unreviewed
CVE-2022-42491
was published
Jan 27, 2023
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing...
Critical
Unreviewed
CVE-2022-41016
was published
Jan 27, 2023
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing...
Critical
Unreviewed
CVE-2022-41019
was published
Jan 27, 2023
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing...
Critical
Unreviewed
CVE-2022-41017
was published
Jan 27, 2023
Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing...
Critical
Unreviewed
CVE-2022-41030
was published
Jan 27, 2023
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to...
Critical
Unreviewed
CVE-2022-46967
was published
Jan 27, 2023
Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
Critical
Unreviewed
CVE-2022-46966
was published
Jan 27, 2023
flash_tool Gem for Ruby File Download Handling Arbitrary Command Execution
Critical
CVE-2013-2513
was published
for
flash_tool
(RubyGems)
Jan 26, 2023
An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model...
Critical
Unreviewed
CVE-2020-18330
was published
Jan 26, 2023
phpmyadmin contains SQL Injection vulnerability
Critical
CVE-2020-22452
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 26, 2023
Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running...
Critical
Unreviewed
CVE-2020-18331
was published
Jan 26, 2023
A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud...
Critical
Unreviewed
CVE-2022-29843
was published
Jan 26, 2023
A vulnerability in the FTP service of Western Digital My Cloud OS 5 devices running firmware...
Critical
Unreviewed
CVE-2022-29844
was published
Jan 26, 2023
Remote Code Execution in com.bstek.uflo:uflo-core
Critical
CVE-2022-25894
was published
for
com.bstek.uflo:uflo-core
(Maven)
Jan 26, 2023
Remote code execution in simple-git
Critical
CVE-2022-25860
was published
for
simple-git
(npm)
Jan 26, 2023
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated,...
Critical
Unreviewed
CVE-2022-31706
was published
Jan 26, 2023
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated...
Critical
Unreviewed
CVE-2022-31704
was published
Jan 26, 2023
Command injection in vagrant.js
Critical
CVE-2022-25962
was published
for
vagrant.js
(npm)
Jan 26, 2023
Command Injection in create-choo-electron
Critical
CVE-2022-25908
was published
for
create-choo-electron
(npm)
Jan 26, 2023
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and...
Critical
Unreviewed
CVE-2022-40037
was published
Jan 26, 2023
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
Critical
Unreviewed
CVE-2022-44297
was published
Jan 26, 2023
An issue in the website background of taocms v3.0.2 allows attackers to execute a Server-Side...
Critical
Unreviewed
CVE-2022-46998
was published
Jan 26, 2023
Tuzicms v2.0.6 was discovered to contain a SQL injection vulnerability via the component \App...
Critical
Unreviewed
CVE-2022-46999
was published
Jan 26, 2023
A backdoor in Solar-Log Gateway products allows remote access via web panel gaining super...
Critical
Unreviewed
CVE-2022-47767
was published
Jan 26, 2023
ProTip!
Advisories are also available from the
GraphQL API