GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
86,158 advisories
Filter by severity
The 140+ Widgets | Best Addons For Elementor – FREE for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2024-4471
was published
May 23, 2024
The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to PHP Object...
High
Unreviewed
CVE-2024-5085
was published
May 23, 2024
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is...
High
Unreviewed
CVE-2024-4779
was published
May 23, 2024
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds...
High
Unreviewed
CVE-2024-30280
was published
May 23, 2024
Acrobat Reader versions 20.005.30574, 24.002.20736 and earlier are affected by an out-of-bounds...
High
Unreviewed
CVE-2024-30279
was published
May 23, 2024
A XSS condition exists within GitLab in versions 15.11 before 16.10.6, 16.11 before 16.11.3, and...
High
Unreviewed
CVE-2024-4835
was published
May 23, 2024
The Visual Website Collaboration, Feedback & Project Management – Atarim plugin for WordPress is...
High
Unreviewed
CVE-2024-2038
was published
May 23, 2024
The WP Fastest Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up...
High
Unreviewed
CVE-2024-4347
was published
May 23, 2024
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
High
Unreviewed
CVE-2024-4662
was published
May 23, 2024
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is...
High
Unreviewed
CVE-2024-4978
was published
May 23, 2024
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local...
High
Unreviewed
CVE-2024-29853
was published
May 23, 2024
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
High
Unreviewed
CVE-2024-29850
was published
May 23, 2024
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise...
High
Unreviewed
CVE-2024-29851
was published
May 23, 2024
GStreamer EXIF Metadata Parsing Integer Overflow Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-4453
was published
May 22, 2024
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability....
High
Unreviewed
CVE-2024-4454
was published
May 22, 2024
Avira Prime Link Following Local Privilege Escalation Vulnerability. This vulnerability allows...
High
Unreviewed
CVE-2023-51636
was published
May 22, 2024
IBM Performance Tools for i 7.2, 7.3, 7.4, and 7.5 could allow a local user to gain elevated...
High
Unreviewed
CVE-2024-27264
was published
May 22, 2024
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically...
High
Unreviewed
CVE-2024-4267
was published
May 22, 2024
Qlik Sense Enterprise for Windows before 14.187.4 allows a remote attacker to elevate their...
High
Unreviewed
CVE-2024-36077
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2024-20360
was published
May 22, 2024
A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC)...
High
Unreviewed
CVE-2023-20239
was published
May 22, 2024
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
High
Unreviewed
CVE-2024-4262
was published
May 22, 2024
The Memberpress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all...
High
Unreviewed
CVE-2024-5031
was published
May 22, 2024
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin...
High
Unreviewed
CVE-2024-4157
was published
May 22, 2024
The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Sensitive...
High
Unreviewed
CVE-2024-2088
was published
May 22, 2024
ProTip!
Advisories are also available from the
GraphQL API