GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
121 advisories
Filter by severity
amano Xparc parking solutions 7.1.3879 was discovered to be vulnerable to local file inclusion.
High
Unreviewed
CVE-2023-23330
was published
Mar 28, 2023
Files or Directories Accessible to External Parties vulnerability in Saysis Starcities allows...
High
Unreviewed
CVE-2023-1246
was published
Mar 10, 2023
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the...
High
Unreviewed
CVE-2023-26948
was published
Mar 9, 2023
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the...
High
Unreviewed
CVE-2023-26956
was published
Mar 8, 2023
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user...
High
Unreviewed
CVE-2023-0331
was published
Feb 27, 2023
A Path Traversal in setup.php in OpenEMR < 7.0.0 allows remote unauthenticated users to read...
High
Unreviewed
CVE-2023-22974
was published
Feb 22, 2023
The affected product DIAEnergie (versions prior to v1.9.03.001) contains improper authorization,...
High
Unreviewed
CVE-2023-0822
was published
Feb 17, 2023
CRMEB 4.4.4 is vulnerable to Any File download.
High
Unreviewed
CVE-2022-44343
was published
Feb 6, 2023
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the...
High
Unreviewed
CVE-2022-48161
was published
Feb 1, 2023
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it...
High
Unreviewed
CVE-2022-4140
was published
Jan 3, 2023
The Wholesale Market for WooCommerce WordPress plugin before 1.0.7 does not have authorisation...
High
Unreviewed
CVE-2022-4106
was published
Dec 19, 2022
The web portal of Dragino Lora LG01 18ed40 IoT v4.3.4 has the directory listing at the URL https:...
High
Unreviewed
CVE-2022-45227
was published
Dec 12, 2022
WAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030...
High
Unreviewed
CVE-2022-44356
was published
Nov 29, 2022
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive...
High
Unreviewed
CVE-2022-3691
was published
Nov 21, 2022
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
High
Unreviewed
CVE-2022-44583
was published
Nov 19, 2022
Payara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF...
High
Unreviewed
CVE-2022-45129
was published
Nov 10, 2022
There is a file inclusion vulnerability in the template management module in UCMS 1.6
High
Unreviewed
CVE-2022-42234
was published
Oct 14, 2022
A misconfiguration in the Service Mode profile directory of Clash for Windows v0.19.9 allows...
High
Unreviewed
CVE-2022-40126
was published
Sep 30, 2022
Tenda AC6(AC1200) v5.0 Firmware v02.03.01.114 and below contains an issue in the component /cgi...
High
Unreviewed
CVE-2022-36552
was published
Aug 31, 2022
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how...
High
Unreviewed
CVE-2022-1117
was published
Aug 29, 2022
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation...
High
Unreviewed
CVE-2021-4112
was published
Aug 26, 2022
A flaw was found in glib before version 2.63.6. Due to random charset alias, pkexec can leak...
High
Unreviewed
CVE-2021-3800
was published
Aug 24, 2022
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file...
High
Unreviewed
CVE-2022-2357
was published
Aug 9, 2022
The Project Source Code Download WordPress plugin through 1.0.0 does not protect its backup...
High
Unreviewed
CVE-2022-1585
was published
Aug 2, 2022
Trend Micro VPN Proxy Pro version 5.2.1026 and below contains a vulnerability involving some...
High
Unreviewed
CVE-2022-33158
was published
Jul 31, 2022
ProTip!
Advisories are also available from the
GraphQL API