GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
26,868 advisories
Filter by severity
The Fontsy WordPress plugin through 1.8.6 does not properly sanitize and escape a parameter...
Critical
Unreviewed
CVE-2022-4447
was published
Jan 16, 2023
A vulnerability was found in 2071174A vinylmap. It has been classified as critical. Affected is...
Critical
Unreviewed
CVE-2015-10056
was published
Jan 16, 2023
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass...
Critical
Unreviewed
CVE-2019-13360
was published
May 24, 2022
A vulnerability, which was classified as critical, has been found in risheesh debutsav. This...
Critical
Unreviewed
CVE-2014-125081
was published
Jan 18, 2023
A vulnerability was found in VictorFerraresi pokemon-database-php. It has been declared as...
Critical
Unreviewed
CVE-2015-10064
was published
Jan 17, 2023
A vulnerability, which was classified as problematic, was found in galaxy-data-resource up to 14...
Critical
Unreviewed
CVE-2015-10062
was published
Jan 17, 2023
A vulnerability was found in nivit redports. It has been declared as critical. This vulnerability...
Critical
Unreviewed
CVE-2014-125082
was published
Jan 18, 2023
A vulnerability classified as critical was found in AenBleidd FiND. This vulnerability affects...
Critical
Unreviewed
CVE-2015-10065
was published
Jan 18, 2023
A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects...
Critical
Unreviewed
CVE-2015-10055
was published
Jan 16, 2023
A vulnerability classified as critical has been found in PrivateSky apersistence. This affects an...
Critical
Unreviewed
CVE-2017-20171
was published
Jan 18, 2023
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4235
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4239
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4240
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4246
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4244
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4245
was published
May 14, 2022
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X...
Critical
Unreviewed
CVE-2016-4242
was published
May 14, 2022
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection
Critical
CVE-2023-22727
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
Critical
CVE-2023-22731
was published
for
shopware/core
(Composer)
Jan 17, 2023
** UNSUPPPORTED WHEN ASSIGNED **** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in...
Critical
Unreviewed
CVE-2010-10007
was published
Jan 18, 2023
Keycloak vulnerable to path traversal via double URL encoding
Critical
CVE-2022-3782
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 13, 2022
festivaltts4r allows arbitrary command execution
Critical
CVE-2016-10194
was published
for
festivaltts4r
(RubyGems)
Oct 24, 2017
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before...
Critical
Unreviewed
CVE-2016-7020
was published
May 14, 2022
Jeecg-boot is vulnerable to SQL injection
Critical
CVE-2022-47105
was published
for
org.jeecgframework.boot:jeecg-boot-base-core
(Maven)
Jan 19, 2023
paperclip Server-Side Request Forgery vulnerability
Critical
CVE-2017-0889
was published
for
paperclip
(RubyGems)
Jan 22, 2018
ProTip!
Advisories are also available from the
GraphQL API