GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
243,852 advisories
Filter by severity
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via...
High
Unreviewed
CVE-2024-55272
was published
Feb 8, 2025
Bento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
Moderate
Unreviewed
CVE-2023-29574
was published
Apr 12, 2023
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via...
Critical
Unreviewed
CVE-2024-55215
was published
Feb 8, 2025
SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2...
High
Unreviewed
CVE-2024-57606
was published
Feb 8, 2025
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component...
Moderate
Unreviewed
CVE-2023-29580
was published
Apr 12, 2023
Cesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c....
Moderate
Unreviewed
CVE-2023-29571
was published
Apr 12, 2023
Use after free in V8 in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2025-0445
was published
Feb 4, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Files or...
Moderate
Unreviewed
CVE-2024-48019
was published
Feb 4, 2025
Use after free in Skia in Google Chrome prior to 133.0.6943.53 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2025-0444
was published
Feb 4, 2025
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in the LDAP User Manager...
Moderate
Unreviewed
CVE-2024-57279
was published
Feb 8, 2025
An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to...
High
Unreviewed
CVE-2024-57357
was published
Feb 8, 2025
A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This...
Moderate
Unreviewed
CVE-2025-1113
was published
Feb 8, 2025
A reflected Cross-Site Scripting (XSS) vulnerability exists in /webscan/sqlmap/index.html in...
Moderate
Unreviewed
CVE-2024-57278
was published
Feb 8, 2025
Inappropriate implementation in Extensions API in Google Chrome prior to 133.0.6943.53 allowed a...
Moderate
Unreviewed
CVE-2025-0451
was published
Feb 4, 2025
A vulnerability classified as problematic has been found in newbee-mall 1.0. Affected is the...
Moderate
Unreviewed
CVE-2025-1114
was published
Feb 8, 2025
Dell PowerProtect DD versions prior to 7.10.1.50 and 7.13.1.20 contain a Stack-based Buffer...
Low
Unreviewed
CVE-2024-53296
was published
Feb 1, 2025
An untrusted search path vulnerability in testinitsigs.exe as used in Bitdefender Antivirus Free...
High
Unreviewed
CVE-2020-8094
was published
Jan 15, 2025
Dell PowerProtect DD versions prior to DDOS 8.3.0.0, 7.10.1.50, and 7.13.1.20 contain a path...
High
Unreviewed
CVE-2024-51534
was published
Feb 1, 2025
An Improper Handling of Exceptional Conditions vulnerability in Juniper Networks Junos OS and...
Moderate
Unreviewed
CVE-2024-30380
was published
Apr 16, 2024
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's...
Moderate
Unreviewed
CVE-2024-2871
was published
Apr 9, 2024
The WooCommerce - Social Login plugin for WordPress is vulnerable to PHP Object Injection in all...
Critical
Unreviewed
CVE-2024-5871
was published
Jun 15, 2024
The User Shortcodes Plus plugin for WordPress is vulnerable to Insecure Direct Object Reference...
Moderate
Unreviewed
CVE-2023-6969
was published
Mar 13, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Themify Themify Builder.This issue affects...
Moderate
Unreviewed
CVE-2024-24872
was published
Feb 21, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2024-31260
was published
Apr 7, 2024
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in...
High
Unreviewed
CVE-2024-2224
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API