GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
218,409 advisories
Filter by severity
The PayPal Pay Now, Buy Now, Donation and Cart Buttons Shortcode plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-3065
was published
May 23, 2024
The Awesome Contact Form7 for Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-4486
was published
May 23, 2024
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is...
High
Unreviewed
CVE-2024-4978
was published
May 23, 2024
The wpDataTables – WordPress Data Table, Dynamic Tables & Table Charts Plugin plugin for...
Moderate
Unreviewed
CVE-2024-4895
was published
May 23, 2024
A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0 and...
Moderate
Unreviewed
CVE-2024-5231
was published
May 23, 2024
A vulnerability has been found in EnvaySoft FleetCart up to 4.1.1 and classified as problematic....
Moderate
Unreviewed
CVE-2024-5230
was published
May 23, 2024
The WPCafe – Restaurant Menu, Online Ordering for WooCommerce, Pickup / Delivery and Table...
Moderate
Unreviewed
CVE-2024-1855
was published
May 23, 2024
The iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2023-6844
was published
May 23, 2024
A condition exists in lighttpd version prior to 1.4.51 whereby a remote attacker can craft an...
Unknown
Unreviewed
CVE-2024-3708
was published
May 23, 2024
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local...
High
Unreviewed
CVE-2024-29853
was published
May 23, 2024
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise...
Critical
Unreviewed
CVE-2024-29849
was published
May 23, 2024
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
Low
Unreviewed
CVE-2024-29852
was published
May 23, 2024
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
High
Unreviewed
CVE-2024-29850
was published
May 23, 2024
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise...
High
Unreviewed
CVE-2024-29851
was published
May 23, 2024
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an...
Moderate
Unreviewed
CVE-2023-46806
was published
May 23, 2024
An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated...
Moderate
Unreviewed
CVE-2023-46807
was published
May 23, 2024
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local...
Moderate
Unreviewed
CVE-2024-22026
was published
May 23, 2024
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-4454
was published
May 22, 2024
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-4453
was published
May 22, 2024
tileserver-gl up to v4.4.10 was discovered to contain a cross-site scripting (XSS) vulnerability...
Unknown
Unreviewed
CVE-2024-35627
was published
May 22, 2024
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2023-51636
was published
May 22, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31894
was published
May 22, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31895
was published
May 22, 2024
IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain...
Moderate
Unreviewed
CVE-2024-31893
was published
May 22, 2024
Sante PACS Server PG Patient Query SQL Injection Remote Code Execution Vulnerability. This...
Critical
Unreviewed
CVE-2023-51637
was published
May 22, 2024
ProTip!
Advisories are also available from the
GraphQL API