GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
4,554 advisories
Filter by severity
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not...
High
Unreviewed
CVE-2024-40721
was published
Aug 2, 2024
A path hijacking vulnerability was reported in Lenovo Driver Manager prior to version 3.1.1307...
High
Unreviewed
CVE-2023-1577
was published
Jul 31, 2024
Improper Input Validation vulnerability in Cato Networks SDP Client on Windows allows OS Command...
High
Unreviewed
CVE-2024-6973
was published
Jul 31, 2024
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data...
High
Unreviewed
CVE-2024-39950
was published
Jul 31, 2024
A vulnerability has been found in Dahua products.Attackers
can send carefully crafted data...
High
Unreviewed
CVE-2024-39944
was published
Jul 31, 2024
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data...
High
Unreviewed
CVE-2024-39948
was published
Jul 31, 2024
A vulnerability has been found in Dahua products. Attackers can send carefully crafted data...
High
Unreviewed
CVE-2024-39949
was published
Jul 31, 2024
Apache Traffic Server accepts characters that are not allowed for HTTP field names and forwards...
High
Unreviewed
CVE-2023-38522
was published
Jul 26, 2024
Invalid Accept-Encoding header can cause Apache Traffic Server to fail cache lookup and force...
High
Unreviewed
CVE-2024-35296
was published
Jul 26, 2024
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android...
High
Unreviewed
CVE-2024-7014
was published
Jul 23, 2024
Insufficient data validation in DevTools in Google Chrome prior to 121.0.6167.85 allowed a remote...
High
Unreviewed
CVE-2024-3172
was published
Jul 17, 2024
Insufficient data validation in Updater in Google Chrome prior to 120.0.6099.62 allowed a remote...
High
Unreviewed
CVE-2024-3173
was published
Jul 17, 2024
Insufficient data validation in Permission Prompts in Google Chrome prior to 117.0.5938.62...
High
Unreviewed
CVE-2023-7012
was published
Jul 17, 2024
An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a...
High
Unreviewed
CVE-2024-6089
was published
Jul 16, 2024
Improper input validation in the installer for some Zoom Apps for Windows may allow an...
High
Unreviewed
CVE-2024-27240
was published
Jul 15, 2024
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by...
High
Unreviewed
CVE-2024-40520
was published
Jul 12, 2024
SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is caused by...
High
Unreviewed
CVE-2024-40518
was published
Jul 12, 2024
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service,...
High
Unreviewed
CVE-2024-5681
was published
Jul 11, 2024
In newServiceInfoLocked of AutofillManagerServiceImpl.java, there is a possible way to hide an...
High
Unreviewed
CVE-2024-31310
was published
Jul 9, 2024
PowerShell Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38043
was published
Jul 9, 2024
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38052
was published
Jul 9, 2024
PowerShell Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38033
was published
Jul 9, 2024
Microsoft Office Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-38021
was published
Jul 9, 2024
PowerShell Elevation of Privilege Vulnerability
High
Unreviewed
CVE-2024-38047
was published
Jul 9, 2024
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to...
High
Unreviewed
CVE-2024-39573
was published
Jul 1, 2024
ProTip!
Advisories are also available from the
GraphQL API