GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,678
Erlang
29
GitHub Actions
16
Go
1,707
Maven
4,940
npm
3,471
NuGet
603
pip
2,993
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
237,273 advisories
Filter by severity
ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool`
Moderate
GHSA-2557-x9mg-76w8
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 21, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35090
was published
May 23, 2024
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-4365
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35083
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35082
was published
May 23, 2024
Certain HP LaserJet Pro devices are potentially vulnerable to a Cross-Site Scripting (XSS) attack...
Unknown
Unreviewed
CVE-2024-2301
was published
May 23, 2024
A user with device administrative privileges can change existing SMTP server settings on the...
Unknown
Unreviewed
CVE-2024-5143
was published
May 23, 2024
A SQL injection vulnerability in /view/conversation_history_admin.php in Campcodes Complete Web...
Unknown
Unreviewed
CVE-2024-34935
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35091
was published
May 23, 2024
A SQL injection vulnerability in /model/update_classroom.php in Campcodes Complete Web-Based...
Unknown
Unreviewed
CVE-2024-34927
was published
May 23, 2024
A SQL injection vulnerability in /view/find_friends.php in Campcodes Complete Web-Based School...
Unknown
Unreviewed
CVE-2024-34929
was published
May 23, 2024
A SQL injection vulnerability in /model/update_subject_routing.php in Campcodes Complete Web...
Unknown
Unreviewed
CVE-2024-34928
was published
May 23, 2024
A SQL injection vulnerability in /model/update_grade.php in Campcodes Complete Web-Based School...
Unknown
Unreviewed
CVE-2024-34933
was published
May 23, 2024
A SQL injection vulnerability in /model/update_subject.php in Campcodes Complete Web-Based School...
Unknown
Unreviewed
CVE-2024-34931
was published
May 23, 2024
A SQL injection vulnerability in /model/all_events1.php in Campcodes Complete Web-Based School...
Unknown
Unreviewed
CVE-2024-34930
was published
May 23, 2024
A SQL injection vulnerability in /view/emarks_range_grade_update_form.php in Campcodes Complete...
Unknown
Unreviewed
CVE-2024-34934
was published
May 23, 2024
LuckyFrameWeb v3.5.2 was discovered to contain an arbitrary file deletion vulnerability via the...
Unknown
Unreviewed
CVE-2024-35081
was published
May 23, 2024
A SQL injection vulnerability in /view/event1.php in Campcodes Complete Web-Based School...
Unknown
Unreviewed
CVE-2024-34936
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35086
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35085
was published
May 23, 2024
J2EEFAST v2.7.0 was discovered to contain a SQL injection vulnerability via the findPage function...
Unknown
Unreviewed
CVE-2024-35084
was published
May 23, 2024
A flaw was found in PCP. The default pmproxy configuration exposes the Redis server backend to...
High
Unreviewed
CVE-2024-3019
was published
Mar 28, 2024
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of user role and title of user...
Unknown
Unreviewed
CVE-2024-33526
was published
May 21, 2024
A Stored Cross-site Scripting (XSS) vulnerability in the "Import of Users and login name of user"...
Unknown
Unreviewed
CVE-2024-33527
was published
May 21, 2024
ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated...
Unknown
Unreviewed
CVE-2024-33529
was published
May 21, 2024
ProTip!
Advisories are also available from the
GraphQL API