GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,748
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
25,817 advisories
Filter by severity
Purchase Order Management System v1.0 contains a file upload vulnerability via /purchase_order...
Critical
Unreviewed
CVE-2022-44400
was published
Nov 28, 2022
SQL injection in School Management System 1.0 allows remote attackers to modify or delete data,...
Critical
Unreviewed
CVE-2022-36193
was published
Nov 28, 2022
Online Tours & Travels Management System v1.0 contains an arbitrary file upload vulnerability via...
Critical
Unreviewed
CVE-2022-44401
was published
Nov 28, 2022
The Export customers list csv for WooCommerce, WordPress users csv, export Guest customer list...
Critical
Unreviewed
CVE-2022-3603
was published
Nov 28, 2022
KubeView vulnerable to full cluster takeover due to improper authentication
Critical
CVE-2022-45933
was published
for
github.com/benc-uk/kubeview
(Go)
Nov 27, 2022
PaddlePaddle vulnerable to code injection via winstr
Critical
CVE-2022-45908
was published
for
paddlepaddle
(pip)
Nov 26, 2022
drachtio-server 0.8.18 has a heap-based buffer over-read via a long Request-URI in an INVITE...
Critical
Unreviewed
CVE-2022-45909
was published
Nov 26, 2022
PyTorch vulnerable to arbitrary code execution
Critical
CVE-2022-45907
was published
for
torch
(pip)
Nov 26, 2022
A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the...
Critical
Unreviewed
CVE-2022-41157
was published
Nov 25, 2022
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection...
Critical
Unreviewed
CVE-2022-44844
was published
Nov 25, 2022
Moodle blind Server-Side Request Forgery (SSRF) vulnerability in LTI provider library
Critical
CVE-2022-45152
was published
for
moodle/moodle
(Composer)
Nov 25, 2022
Remote code execution vulnerability can be achieved by using cookie values as paths to a file by...
Critical
Unreviewed
CVE-2022-41158
was published
Nov 25, 2022
Orchardproject Orchard CMS 1.10.3 is vulnerable to Cross Site Scripting (XSS). When a low...
Critical
Unreviewed
CVE-2022-37720
was published
Nov 25, 2022
PyroCMS vulnerable to stored Cross Site Scripting
Critical
CVE-2022-37721
was published
for
pyrocms/pyrocms
(Composer)
Nov 25, 2022
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 25, 2022
Badaso vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-41705
was published
for
badaso/core
(Composer)
Nov 25, 2022
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500...
Critical
Unreviewed
CVE-2022-36133
was published
Nov 25, 2022
Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 all versions...
Critical
Unreviewed
CVE-2022-29830
was published
Nov 25, 2022
wger vulnerable to brute force attempts
Critical
CVE-2022-2650
was published
for
wger
(pip)
Nov 24, 2022
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected...
Critical
Unreviewed
CVE-2022-4088
was published
Nov 24, 2022
Attackers can call any existing functions at will, control the target server to access, download,...
Critical
Unreviewed
CVE-2022-4136
was published
Nov 24, 2022
iTerm2 before 3.4.18 mishandles a DECRQSS response.
Critical
Unreviewed
CVE-2022-45872
was published
Nov 24, 2022
An issue in the /index/user/user_edit.html component of YJCMS v1.0.9 allows unauthenticated...
Critical
Unreviewed
CVE-2022-45276
was published
Nov 23, 2022
ProTip!
Advisories are also available from the
GraphQL API