GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,840
Erlang
36
GitHub Actions
33
Go
2,464
Maven
5,000+
npm
4,082
NuGet
723
pip
3,880
Pub
12
RubyGems
943
Rust
1,011
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,665 advisories
Filter by severity
Campbell Scientific dataloggers CR6, CR300, CR800, CR1000 and CR3000 may allow an attacker to...
Critical
Unreviewed
CVE-2023-0321
was published
Jan 26, 2023
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3...
Critical
Unreviewed
CVE-2023-24022
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/fromSetWirelessRepeat.
Critical
Unreviewed
CVE-2023-24170
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/formWifiBasicSet.
Critical
Unreviewed
CVE-2023-24166
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_000c2318.
Critical
Unreviewed
CVE-2023-24164
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/FUN_0007343c.
Critical
Unreviewed
CVE-2023-24169
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/add_white_node.
Critical
Unreviewed
CVE-2023-24167
was published
Jan 26, 2023
Tenda AC18 V15.03.05.19 is vulnerable to Buffer Overflow via /goform/initIpAddrInfo.
Critical
Unreviewed
CVE-2023-24165
was published
Jan 26, 2023
XML external entity reference vulnerability on agents in Jenkins Semantic Versioning Plugin
Critical
CVE-2023-24430
was published
for
org.jenkins-ci.plugins:semantic-versioning-plugin
(Maven)
Jan 26, 2023
XML external entity vulnerability on agents in Jenkins MSTest Plugin
Critical
CVE-2023-24441
was published
for
org.jvnet.hudson.plugins:mstest
(Maven)
Jan 26, 2023
Session fixation vulnerability in Jenkins Keycloak Authentication Plugin
Critical
CVE-2023-24456
was published
for
org.jenkins-ci.plugins:keycloak
(Maven)
Jan 26, 2023
Session fixation vulnerability in Jenkins Bitbucket OAuth Plugin
Critical
CVE-2023-24427
was published
for
org.jenkins-ci.plugins:bitbucket-oauth
(Maven)
Jan 26, 2023
XML Entity Expansion in Jenkins TestComplete support Plugin
Critical
CVE-2023-24443
was published
for
org.jenkins-ci.plugins:TestComplete
(Maven)
Jan 26, 2023
Agent-to-controller security bypass in Jenkins Semantic Versioning Plugin
Critical
CVE-2023-24429
was published
for
org.jenkins-ci.plugins:semantic-versioning-plugin
(Maven)
Jan 26, 2023
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3...
Critical
Unreviewed
CVE-2023-24508
was published
Jan 26, 2023
JWT audience claim is not verified
Critical
CVE-2023-22482
was published
for
github.com/argoproj/argo-cd
(Go)
Jan 25, 2023
Amano Xoffice parking solutions 7.1.3879 is vulnerable to SQL Injection.
Critical
Unreviewed
CVE-2023-23331
was published
Jan 24, 2023
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute...
Critical
Unreviewed
CVE-2022-45639
was published
Jan 24, 2023
MITM based Zip Slip in `ca.uhn.hapi.fhir:org.hl7.fhir.core`
Critical
CVE-2023-24057
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Jan 23, 2023
MITM based Zip Slip in `org.hl7.fhir.publisher:org.hl7.fhir.publisher`
Critical
GHSA-xr8x-pxm6-prjg
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher
(Maven)
Jan 23, 2023
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input...
Critical
Unreviewed
CVE-2023-23560
was published
Jan 23, 2023
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can...
Critical
Unreviewed
CVE-2021-43445
was published
Jan 23, 2023
The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a...
Critical
Unreviewed
CVE-2022-4383
was published
Jan 23, 2023
The WeStand WordPress theme before 2.1, footysquare WordPress theme, aidreform WordPress theme,...
Critical
Unreviewed
CVE-2022-0316
was published
Jan 23, 2023
The Login as User or Customer WordPress plugin before 3.3 lacks authorization checks to ensure...
Critical
Unreviewed
CVE-2022-4305
was published
Jan 23, 2023
ProTip!
Advisories are also available from the
GraphQL API