GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
103,313 advisories
Filter by severity
SQL injection in JeecgBoot
High
CVE-2024-57606
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Feb 8, 2025
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via...
High
Unreviewed
CVE-2024-55272
was published
Feb 8, 2025
Connect-CMS information that is restricted to viewing is visible
High
GHSA-2237-5r9w-vm8j
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2024-9664
was published
Feb 7, 2025
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions...
High
Unreviewed
CVE-2024-7419
was published
Feb 7, 2025
An improper access control vulnerability may allow privilege escalation.This issue affects:
*...
High
Unreviewed
CVE-2022-26389
was published
Feb 7, 2025
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to...
High
Unreviewed
CVE-2024-55214
was published
Feb 7, 2025
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to...
High
Unreviewed
CVE-2024-52881
was published
Feb 7, 2025
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to...
High
Unreviewed
CVE-2024-55213
was published
Feb 7, 2025
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501...
High
Unreviewed
CVE-2024-52884
was published
Feb 7, 2025
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a...
High
Unreviewed
CVE-2024-52883
was published
Feb 7, 2025
Tally Prime Edit Log v2.1 was discovered to contain a DLL hijacking vulnerability via the...
High
Unreviewed
CVE-2024-48091
was published
Feb 7, 2025
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN...
High
Unreviewed
CVE-2024-10383
was published
Feb 7, 2025
A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802....
High
Unreviewed
CVE-2025-1103
was published
Feb 7, 2025
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This...
High
Unreviewed
CVE-2025-1108
was published
Feb 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-25141
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile allows Stored...
High
Unreviewed
CVE-2025-25140
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications allows...
High
Unreviewed
CVE-2025-25154
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box allows Stored XSS....
High
Unreviewed
CVE-2025-25149
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments allows Stored...
High
Unreviewed
CVE-2025-25156
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link allows Stored...
High
Unreviewed
CVE-2025-25148
was published
Feb 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-25155
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker allows Stored XSS....
High
Unreviewed
CVE-2025-25160
was published
Feb 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-25159
was published
Feb 7, 2025
ProTip!
Advisories are also available from the
GraphQL API