GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
120 advisories
Filter by severity
The discontinued FFS Colibri product allows a remote user to access files on the system including...
Moderate
Unreviewed
CVE-2023-5885
was published
Nov 28, 2023
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter....
High
Unreviewed
CVE-2023-6252
was published
Nov 22, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program,
has found that the VAPIX API...
High
Unreviewed
CVE-2023-21417
was published
Nov 21, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API irissetup...
High
Unreviewed
CVE-2023-21418
was published
Nov 21, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API...
High
Unreviewed
CVE-2023-21416
was published
Nov 21, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43803
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - local privilege escalation vulnerability
High
CVE-2023-43802
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Arduino Create Agent path traversal - arbitrary file deletion vulnerability
Moderate
CVE-2023-43801
was published
for
github.com/arduino/arduino-create-agent
(Go)
Oct 18, 2023
Sandro Poppi, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API overlay_del...
High
Unreviewed
CVE-2023-21415
was published
Oct 16, 2023
NLnet Labs’ Routinator 0.9.0 up to and including 0.12.1 contains a possible path traversal...
Moderate
Unreviewed
CVE-2023-39916
was published
Sep 13, 2023
In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a...
High
Unreviewed
CVE-2023-32714
was published
Jun 1, 2023
In JetBrains Ktor before 2.3.0 path traversal in the `resolveResource` method was possible
High
Unreviewed
CVE-2022-48476
was published
Apr 24, 2023
The File Management System developed by FileOrbis before version 10.6.3 has an unauthenticated...
High
Unreviewed
CVE-2022-3693
was published
Jan 13, 2023
The Identity and Directory Management System developed by Çekino Bilgi Teknolojileri before...
High
Unreviewed
CVE-2022-2265
was published
Sep 22, 2022
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service ...
Moderate
Unreviewed
CVE-2021-1364
was published
May 24, 2022
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service ...
Moderate
Unreviewed
CVE-2021-1355
was published
May 24, 2022
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service ...
Moderate
Unreviewed
CVE-2021-1357
was published
May 24, 2022
Multiple vulnerabilities in Cisco Unified Communications Manager IM & Presence Service ...
Moderate
Unreviewed
CVE-2021-1282
was published
May 24, 2022
Improper Input Validation in Spring Framework
Moderate
CVE-2020-5421
was published
for
org.springframework:spring-framework-bom
(Maven)
Apr 30, 2021
ProTip!
Advisories are also available from the
GraphQL API