GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
838 advisories
Filter by severity
Magento improper input validation vulnerability
Critical
CVE-2022-24086
was published
for
magento/community-edition
(Composer)
Feb 17, 2022
An improper input validation leading to arbitrary file creation was discovered in ToWord of...
Critical
Unreviewed
CVE-2021-26618
was published
Feb 19, 2022
This issues due to insufficient verification of the various input values from user’s input. The...
Critical
Unreviewed
CVE-2021-26617
was published
Feb 26, 2022
Remote CLI Command Execution Vulnerability in CodeIgniter4
Critical
CVE-2022-24711
was published
for
codeigniter4/framework
(Composer)
Mar 1, 2022
Remote shell execution vulnerability in image_processing
Critical
CVE-2022-24720
was published
for
image_processing
(RubyGems)
Mar 1, 2022
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7...
Critical
Unreviewed
CVE-2021-32586
was published
Mar 2, 2022
In certain situations it is possible for an unmanaged rule to exist on the target system that has...
Critical
Unreviewed
CVE-2022-0675
was published
Mar 3, 2022
SAPCAR - version 7.22, does not contain sufficient input validation on the SAPCAR archive. As a...
Critical
Unreviewed
CVE-2022-26100
was published
Mar 11, 2022
It was discovered that the SteelCentral AppInternals Dynamic Sampling Agent (DSA) has Remote Code...
Critical
Unreviewed
CVE-2021-42786
was published
Mar 11, 2022
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the...
Critical
Unreviewed
CVE-2022-25498
was published
Mar 16, 2022
In the vote (aka "Polls, Votes") module before 21.0.100 of Bitrix Site Manager, a remote...
Critical
Unreviewed
CVE-2022-27228
was published
Mar 23, 2022
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name...
Critical
Unreviewed
CVE-2021-26622
was published
Mar 26, 2022
Sabberworm PHP CSS Parser Code injection vulnerability in allSelectors()
Critical
CVE-2020-13756
was published
for
sabberworm/php-css-parser
(Composer)
Mar 26, 2022
In Apache APISIX before 2.13.0, when decoding JSON with duplicate keys, lua-cjson will choose the...
Critical
Unreviewed
CVE-2022-25757
was published
Mar 29, 2022
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware...
Critical
Unreviewed
CVE-2021-32974
was published
Apr 3, 2022
Snoopy 2.0.0-1 has a security hole in exec cURL
Critical
Unreviewed
CVE-2002-2444
was published
Apr 21, 2022
Tiki Wiki CMS Groupware 5.2 has Local File Inclusion
Critical
Unreviewed
CVE-2010-4239
was published
Apr 21, 2022
qtparted has insecure library loading which may allow arbitrary code execution
Critical
Unreviewed
CVE-2010-3375
was published
Apr 21, 2022
Rbot Reaction plugin allows command execution
Critical
Unreviewed
CVE-2010-2446
was published
Apr 21, 2022
In gksu-polkit before 0.0.3, the source file for xauth may contain arbitrary commands that may...
Critical
Unreviewed
CVE-2011-0703
was published
Apr 22, 2022
Smarty3 Arbitrary PHP Code Execution
Critical
CVE-2011-1028
was published
for
smarty/smarty
(Composer)
Apr 22, 2022
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM...
Critical
Unreviewed
CVE-2011-4120
was published
Apr 22, 2022
Input validation issues were found in Calibre at devices/linux_mount_helper.c which can lead to...
Critical
Unreviewed
CVE-2011-4124
was published
Apr 22, 2022
gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables...
Critical
Unreviewed
CVE-2011-2897
was published
Apr 23, 2022
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which...
Critical
Unreviewed
CVE-2012-0694
was published
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API