GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,890
Erlang
37
GitHub Actions
38
Go
2,546
Maven
5,000+
npm
4,217
NuGet
745
pip
3,994
Pub
12
RubyGems
950
Rust
1,038
Swift
45
Unreviewed advisories
All unreviewed
5,000+
358 advisories
Filter by severity
GDidees CMS v3.9.1 was discovered to contain a source code disclosure vulnerability by the backup...
High
Unreviewed
CVE-2023-27180
was published
Apr 7, 2023
An insecure direct object reference vulnerability in GitLab EE affecting all versions from 15.7...
Moderate
Unreviewed
CVE-2025-1042
was published
Feb 12, 2025
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to...
High
Unreviewed
CVE-2024-55213
was published
Feb 7, 2025
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to...
High
Unreviewed
CVE-2024-55214
was published
Feb 7, 2025
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It...
Moderate
Unreviewed
CVE-2024-5045
was published
May 17, 2024
The EPHEMERAL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers...
Moderate
Unreviewed
CVE-2016-3715
was published
May 14, 2022
Sparkle Signing Checks Bypass
High
CVE-2025-0509
was published
for
github.com/sparkle-project/Sparkle
(Swift)
Feb 4, 2025
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller...
High
Unreviewed
CVE-2024-57452
was published
Feb 3, 2025
Brocade Fabric OS versions before
8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2...
Moderate
Unreviewed
CVE-2024-10403
was published
Feb 4, 2025
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021...
High
Unreviewed
CVE-2023-29080
was published
Jan 30, 2025
?An attacker could bypass the latest Delta Electronics InfraSuite Device Master (versions prior...
High
Unreviewed
CVE-2023-34316
was published
Jul 10, 2023
An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows...
Moderate
Unreviewed
CVE-2024-3037
was published
May 14, 2024
An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before...
Moderate
Unreviewed
CVE-2023-29820
was published
May 12, 2023
An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to...
High
Unreviewed
CVE-2024-45276
was published
Oct 15, 2024
IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2024-47106
was published
Jan 18, 2025
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V9.80), SIPROTEC...
High
Unreviewed
CVE-2024-53649
was published
Jan 14, 2025
Specially constructed queries targeting ETM could discover active remote access sessions
Moderate
Unreviewed
CVE-2024-47518
was published
Jan 11, 2025
The CGI script <redacted>.sh can be used to download any file on the filesystem.
This issue...
High
Unreviewed
CVE-2024-43660
was published
Jan 9, 2025
SiYuan has an arbitrary file deletion vulnerability
High
CVE-2025-21609
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jan 3, 2025
A widget local file inclusion vulnerability in Trend Micro Apex One could allow a remote attacker...
High
Unreviewed
CVE-2024-52047
was published
Dec 31, 2024
Gogs allows deletion of internal files
Critical
CVE-2024-39931
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Duplicate Advisory: Gogs allows deletion of internal files
Critical
GHSA-2vgj-3pvg-xh4w
was published
for
github.com/gogs/gogs
(Go)
Jul 4, 2024
•
withdrawn
jfinal CMS 5.1.0 has an arbitrary file read vulnerability.
High
Unreviewed
CVE-2023-34645
was published
Jun 16, 2023
An issue was discovered in Digi ConnectPort LTS before 1.4.12. A Privilege Escalation...
High
Unreviewed
CVE-2024-50627
was published
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API