GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
25,562 advisories
Filter by severity
ELITE TECHNOLOGY CORP. Web Fax has a vulnerability of SQL Injection. An unauthenticated remote...
Critical
Unreviewed
CVE-2023-28701
was published
Jun 2, 2023
It is identified a vulnerability of insufficient authentication in the system configuration...
Critical
Unreviewed
CVE-2023-30604
was published
Jun 2, 2023
Wade Graphic Design FANTSY has a vulnerability of insufficient authorization check. An...
Critical
Unreviewed
CVE-2023-28698
was published
Jun 2, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-3000
was published
Jun 2, 2023
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can...
Critical
Unreviewed
CVE-2022-45938
was published
Jun 2, 2023
An issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code...
Critical
Unreviewed
CVE-2023-29746
was published
Jun 2, 2023
Keyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows...
Critical
Unreviewed
CVE-2023-29736
was published
Jun 1, 2023
The Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively...
Critical
Unreviewed
CVE-2023-29722
was published
Jun 1, 2023
In Splunk App for Stream versions below 8.1.1, a low-privileged user could use a vulnerability in...
Critical
Unreviewed
CVE-2023-32713
was published
Jun 1, 2023
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote...
Critical
Unreviewed
CVE-2022-4333
was published
Jun 1, 2023
Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below...
Critical
Unreviewed
CVE-2023-33778
was published
Jun 1, 2023
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to...
Critical
Unreviewed
CVE-2023-23952
was published
Jun 1, 2023
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Critical
Unreviewed
CVE-2022-35744
was published
May 31, 2023
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21,...
Critical
Unreviewed
CVE-2021-45039
was published
May 31, 2023
D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability...
Critical
Unreviewed
CVE-2023-33735
was published
May 31, 2023
Privilege Escalation in the "GetUserCurrentPwd" function in Microworld Technologies eScan...
Critical
Unreviewed
CVE-2023-33730
was published
May 31, 2023
** DISPUTED ** An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration...
Critical
Unreviewed
CVE-2023-34257
was published
May 31, 2023
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the...
Critical
Unreviewed
CVE-2023-29747
was published
May 31, 2023
In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin...
Critical
Unreviewed
CVE-2023-34218
was published
May 31, 2023
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a command insertion...
Critical
Unreviewed
CVE-2023-33487
was published
May 31, 2023
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion...
Critical
Unreviewed
CVE-2023-33486
was published
May 31, 2023
EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond...
Critical
Unreviewed
CVE-2023-2909
was published
May 31, 2023
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client....
Critical
Unreviewed
CVE-2023-25539
was published
May 31, 2023
The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of...
Critical
Unreviewed
CVE-2023-2987
was published
May 31, 2023
An issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to...
Critical
Unreviewed
CVE-2023-29739
was published
May 31, 2023
ProTip!
Advisories are also available from the
GraphQL API