GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,653
Erlang
29
GitHub Actions
16
Go
1,706
Maven
4,938
npm
3,471
NuGet
603
pip
2,985
Pub
10
RubyGems
826
Rust
772
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
86,152 advisories
Filter by severity
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is...
High
Unreviewed
CVE-2024-4978
was published
May 23, 2024
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local...
High
Unreviewed
CVE-2024-29853
was published
May 23, 2024
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
High
Unreviewed
CVE-2024-29850
was published
May 23, 2024
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise...
High
Unreviewed
CVE-2024-29851
was published
May 23, 2024
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-4454
was published
May 22, 2024
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-4453
was published
May 22, 2024
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2023-51636
was published
May 22, 2024
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated...
High
Unreviewed
CVE-2024-27264
was published
May 22, 2024
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically...
High
Unreviewed
CVE-2024-4267
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2023-20239
was published
May 22, 2024
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their...
High
Unreviewed
CVE-2024-36077
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2024-20360
was published
May 22, 2024
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2024-4262
was published
May 22, 2024
The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all...
High
Unreviewed
CVE-2024-5031
was published
May 22, 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin...
High
Unreviewed
CVE-2024-4157
was published
May 22, 2024
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive...
High
Unreviewed
CVE-2024-2088
was published
May 22, 2024
The Media Library Assistant plugin for WordPress is vulnerable to SQL Injection via the plugin's...
High
Unreviewed
CVE-2024-3518
was published
May 22, 2024
There are multiple ways in
LCDS LAquis SCADA for an attacker to access locations outside of...
High
Unreviewed
CVE-2024-5040
was published
May 21, 2024
In RTI Connext Professional 5.3.1 through 6.1.0 before 6.1.1, a buffer overflow in XML parsing...
High
Unreviewed
CVE-2024-25724
was published
May 21, 2024
In lunary-ai/lunary version 1.2.2, an incorrect synchronization vulnerability allows unprivileged...
High
Unreviewed
CVE-2024-4154
was published
May 21, 2024
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write...
High
Unreviewed
CVE-2024-22273
was published
May 21, 2024
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious...
High
Unreviewed
CVE-2024-22274
was published
May 21, 2024
A buffer copy without checking size of input vulnerability has been reported to affect several...
High
Unreviewed
CVE-2024-27130
was published
May 21, 2024
A double free vulnerability has been reported to affect several QNAP operating system versions....
High
Unreviewed
CVE-2024-27127
was published
May 21, 2024
An 'SQL Injection' vulnerability, due to improper neutralization of special elements used in SQL...
High
Unreviewed
CVE-2023-3942
was published
May 21, 2024
ProTip!
Advisories are also available from the
GraphQL API