GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,444
Erlang
29
GitHub Actions
16
Go
1,668
Maven
4,928
npm
3,458
NuGet
595
pip
2,876
Pub
10
RubyGems
823
Rust
766
Swift
34
Unreviewed advisories
All unreviewed
5,000+
1,987 advisories
Filter by severity
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as...
High
Unreviewed
CVE-2024-2642
was published
Mar 20, 2024
RCE in TranformGraph().to_dot_graph function
High
CVE-2023-41334
was published
for
astropy
(pip)
Mar 18, 2024
Outlook for Android Information Disclosure Vulnerability
High
Unreviewed
CVE-2024-26204
was published
Mar 12, 2024
1Panel is vulnerable to command injection
Moderate
CVE-2024-2352
was published
for
github.com/1Panel-dev/1Panel
(Go)
Mar 10, 2024
PaddlePaddle command injection vulnerability
Critical
CVE-2024-0817
was published
for
paddlepaddle
(pip)
Mar 7, 2024
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as...
Moderate
Unreviewed
CVE-2024-1781
was published
Feb 23, 2024
pymatgen vulnerable to arbitrary code execution when parsing a maliciously crafted JonesFaithfulTransformation transformation_string
Critical
CVE-2024-23346
was published
for
pymatgen
(pip)
Feb 21, 2024
When running in appliance mode, an authenticated remote command injection vulnerability exists in...
High
Unreviewed
CVE-2024-22093
was published
Feb 14, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1374
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1378
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1372
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
High
Unreviewed
CVE-2024-1354
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1355
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1369
was published
Feb 13, 2024
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an...
Critical
Unreviewed
CVE-2024-1359
was published
Feb 13, 2024
Azure DevOps Server Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-20667
was published
Feb 13, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2023-47218
was published
Feb 13, 2024
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with...
Critical
Unreviewed
CVE-2023-46687
was published
Feb 9, 2024
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network...
Moderate
Unreviewed
CVE-2023-49716
was published
Feb 9, 2024
An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It...
High
Unreviewed
CVE-2023-40263
was published
Feb 9, 2024
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-24321
was published
Feb 8, 2024
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-23049
was published
Feb 6, 2024
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method...
High
Unreviewed
CVE-2024-22107
was published
Feb 2, 2024
An OS command injection vulnerability has been reported to affect Photo Station. If exploited,...
High
Unreviewed
CVE-2023-47562
was published
Feb 2, 2024
An OS command injection vulnerability has been reported to affect several QNAP operating system...
Moderate
Unreviewed
CVE-2023-41281
was published
Feb 2, 2024
ProTip!
Advisories are also available from the
GraphQL API