GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
367 advisories
Filter by severity
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
Low
Unreviewed
CVE-2018-20873
was published
May 24, 2022
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
Low
Unreviewed
CVE-2018-20893
was published
May 24, 2022
The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in...
Low
Unreviewed
CVE-2013-4558
was published
May 17, 2022
When curl is used to retrieve and parse cookies from a HTTP(S) server, itaccepts cookies using...
Low
Unreviewed
CVE-2022-35252
was published
Sep 25, 2022
NVIDIA nvTIFF Library for Windows and Linux contains a vulnerability where improper input...
Low
Unreviewed
CVE-2024-0080
was published
Apr 5, 2024
NVIDIA nvJPEG2000 Library for Windows and Linux contains a vulnerability where improper input...
Low
Unreviewed
CVE-2023-31028
was published
Apr 5, 2024
A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased...
Low
Unreviewed
CVE-2023-2961
was published
Jun 6, 2023
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
Low
Unreviewed
CVE-2017-18458
was published
May 24, 2022
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple...
Low
Unreviewed
CVE-2017-18392
was published
May 24, 2022
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation...
Low
Unreviewed
CVE-2018-20897
was published
May 24, 2022
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the...
Low
Unreviewed
CVE-2018-10947
was published
May 24, 2022
Concrete CMS Stored XSS in the Search Field
Low
CVE-2024-3181
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2024
Concrete CMS Stored XSS in the Custom Class page editing
Low
CVE-2024-3179
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2024
Concrete CMS Cross-site Scripting (XSS) in the Advanced File Search Filter
Low
CVE-2024-3178
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2024
Concrete CMS Stored XSS on the calendar color settings screen
Low
CVE-2024-2753
was published
for
concrete5/concrete5
(Composer)
Apr 3, 2024
net/ipv4/udp.c in the Linux kernel before 2.6.29.1 performs an unlocking step in certain...
Low
Unreviewed
CVE-2009-1243
was published
May 2, 2022
Concrete CMS vulnerable to reflected XSS via the Image URL Import Feature
Low
CVE-2024-1246
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Concrete CMS vulnerable to stored XSS in file tags and description attributes
Low
CVE-2024-1245
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Concrete CMS vulnerable to stored XSS via the Role Name field
Low
CVE-2024-1247
was published
for
concrete5/concrete5
(Composer)
Feb 9, 2024
Improper Input Validation vulnerability in the upload functionality for user avatars allows...
Low
Unreviewed
CVE-2024-23790
was published
Jan 29, 2024
IBM Storage Ceph 5.3z1, 5.3z5, and 6.1z1 could allow an authenticated user on the network to...
Low
Unreviewed
CVE-2023-46159
was published
Feb 2, 2024
There is a DLL hijacking vulnerability in ZTE ZXCLOUD iRAI, an attacker could place a fake DLL...
Low
Unreviewed
CVE-2023-41782
was published
Jan 5, 2024
A denial of service vulnerability exists when Microsoft SQL Server Management Studio (SSMS)...
Low
Unreviewed
CVE-2020-1455
was published
May 24, 2022
A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to...
Low
Unreviewed
CVE-2020-0904
was published
May 24, 2022
Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an...
Low
Unreviewed
CVE-2023-22329
was published
Nov 14, 2023
ProTip!
Advisories are also available from the
GraphQL API