GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
30,740 advisories
Filter by severity
Code execution in Embedchain
Critical
CVE-2024-23731
was published
for
embedchain
(pip)
Jan 21, 2024
Unsafe yaml deserialization in llama-hub
Critical
CVE-2024-23730
was published
for
llama-hub
(pip)
Jan 21, 2024
Code Injection in paddlepaddle
Critical
CVE-2024-0521
was published
for
paddlepaddle
(pip)
Jan 20, 2024
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action...
Critical
Unreviewed
CVE-2023-51928
was published
Jan 20, 2024
An arbitrary file upload vulnerability in the uap.framework.rc.itf.IResourceManager interface of...
Critical
Unreviewed
CVE-2023-51924
was published
Jan 20, 2024
An issue in yonyou YonBIP v3_23.05 allows a remote attacker to execute arbitrary code via a...
Critical
Unreviewed
CVE-2023-51906
was published
Jan 20, 2024
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action...
Critical
Unreviewed
CVE-2023-51925
was published
Jan 20, 2024
File upload vulnerability in ejinshan v8+ terminal security system allows attackers to upload...
Critical
Unreviewed
CVE-2021-31314
was published
Jan 20, 2024
An issue in weaver e-cology v.10.0.2310.01 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2023-51892
was published
Jan 20, 2024
YonBIP v3_23.05 was discovered to contain a SQL injection vulnerability via the com.yonyou...
Critical
Unreviewed
CVE-2023-51927
was published
Jan 20, 2024
Duplicate Advisory: Hard-coded credentials in org.folio:mod-data-export-spring
Critical
GHSA-9rhq-86fm-qxqc
was published
for
org.folio:mod-data-export-spring
(Maven)
Jan 20, 2024
•
withdrawn
Duplicate Advisory: Session fixation in Enonic XP
Critical
GHSA-4hrp-m3f2-643j
was published
for
com.enonic.xp:lib-auth
(Maven)
Jan 19, 2024
•
withdrawn
An issue in dom96 Jester v.0.6.0 and before allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-50693
was published
Jan 19, 2024
An issue in dom96 HTTPbeast v.0.4.1 and before allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-50694
was published
Jan 19, 2024
Arbitrary Code Execution in Pillow
Critical
CVE-2023-50447
was published
for
Pillow
(pip)
Jan 19, 2024
Improper access control on nasSvr.php in actidata actiNAS SL 2U-8 RDX 3.2.03-SP1 allows remote...
Critical
Unreviewed
CVE-2023-51947
was published
Jan 19, 2024
An arbitrary file upload vulnerability in Xpand IT Write-back Manager v2.3.1 allows attackers to...
Critical
Unreviewed
CVE-2023-27168
was published
Jan 19, 2024
SunnyToo stblogsearch up to v1.0.0 was discovered to contain a SQL injection vulnerability via...
Critical
Unreviewed
CVE-2023-43985
was published
Jan 19, 2024
In the module "Jms Setting" (jmssetting) from Joommasters for PrestaShop, a guest can perform SQL...
Critical
Unreviewed
CVE-2023-50030
was published
Jan 19, 2024
In the module "Sliding cart block" (blockslidingcart) up to version 2.3.8 from PrestashopModules...
Critical
Unreviewed
CVE-2023-50028
was published
Jan 19, 2024
In the module mib < 1.6.1 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The...
Critical
Unreviewed
CVE-2023-46351
was published
Jan 19, 2024
Cross-Site Request Forgery on any API call in pyLoad may lead to admin privilege escalation
Critical
CVE-2024-22416
was published
for
pyload-ng
(pip)
Jan 19, 2024
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to SQL Injection via...
Critical
Unreviewed
CVE-2024-0705
was published
Jan 19, 2024
ASUS Armoury Crate has a vulnerability in arbitrary file write and allows remote attackers to...
Critical
Unreviewed
CVE-2023-5716
was published
Jan 19, 2024
ProTip!
Advisories are also available from the
GraphQL API