GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,340
Erlang
31
GitHub Actions
22
Go
2,100
Maven
5,000+
npm
3,764
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
129 advisories
Filter by severity
IBM Jazz for Service Management 1.1.3 through 1.1.3.22 could allow a remote attacker to obtain...
Moderate
Unreviewed
CVE-2024-47106
was published
Jan 18, 2025
Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
Moderate
CVE-2024-45627
was published
for
org.apache.linkis:linkis-metadata-query-service-jdbc
(Maven)
Jan 14, 2025
Specially constructed queries targeting ETM could discover active remote access sessions
Moderate
Unreviewed
CVE-2024-47518
was published
Jan 11, 2025
TCPDF Local File Inclusion vulnerability
Moderate
CVE-2024-51058
was published
for
tecnickcom/tcpdf
(Composer)
Nov 26, 2024
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1...
Moderate
Unreviewed
CVE-2024-10126
was published
Nov 20, 2024
A vulnerability in Cisco IND could allow an authenticated, local attacker to read application...
Moderate
Unreviewed
CVE-2023-20039
was published
Nov 15, 2024
Authenticated user can access unintended user capabilities in NetScaler ADC and NetScaler Gateway...
Moderate
Unreviewed
CVE-2024-8535
was published
Nov 12, 2024
In AshPostgres, empty, atomic, non-bulk actions, policy bypass for side-effects vulnerability.
Moderate
CVE-2024-49756
was published
for
ash_postgres
(Erlang)
Oct 23, 2024
A directory listing issue in the baserCMS plugin in D-ZERO CO., LTD. BurgerEditor and...
Moderate
Unreviewed
CVE-2024-44807
was published
Oct 11, 2024
BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin...
Moderate
Unreviewed
CVE-2024-45894
was published
Oct 7, 2024
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security...
Moderate
Unreviewed
CVE-2024-7107
was published
Sep 26, 2024
A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as...
Moderate
Unreviewed
CVE-2024-8655
was published
Sep 10, 2024
Priority – CWE-552: Files or Directories Accessible to External Parties
Moderate
Unreviewed
CVE-2024-41699
was published
Aug 20, 2024
OpenStack Nova vulnerable to unauthorized access to potentially sensitive data
Moderate
CVE-2024-40767
was published
for
Nova
(pip)
Jul 24, 2024
CWE-552: Files or Directories Accessible to External Parties vulnerability exists which may...
Moderate
Unreviewed
CVE-2024-5056
was published
Jun 12, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5, watchOS...
Moderate
Unreviewed
CVE-2024-23282
was published
Jun 10, 2024
A vulnerability was found in Casdoor up to 1.335.0. It has been classified as problematic....
Moderate
Unreviewed
CVE-2024-5587
was published
Jun 2, 2024
A vulnerability was found in SourceCodester Online Birth Certificate Management System 1.0. It...
Moderate
Unreviewed
CVE-2024-5045
was published
May 17, 2024
wolfictl leaks GitHub tokens to remote non-GitHub git servers
Moderate
CVE-2024-35183
was published
for
github.com/wolfi-dev/wolfictl
(Go)
May 15, 2024
Scrapy allows redirect following in protocols other than HTTP
Moderate
GHSA-23j4-mw76-5v7h
was published
for
Scrapy
(pip)
May 14, 2024
An arbitrary file deletion vulnerability exists in PaperCut NG/MF that only affects Windows...
Moderate
Unreviewed
CVE-2024-3037
was published
May 14, 2024
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation...
Moderate
Unreviewed
CVE-2023-39480
was published
May 3, 2024
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This...
Moderate
Unreviewed
CVE-2023-39479
was published
May 3, 2024
In dotCMS dashboard, the Tools and Log Files tabs under System → Maintenance Portlet, which is...
Moderate
Unreviewed
CVE-2024-3164
was published
Apr 2, 2024
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded...
Moderate
Unreviewed
CVE-2023-45594
was published
Mar 5, 2024
ProTip!
Advisories are also available from the
GraphQL API