GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,697
Erlang
34
GitHub Actions
28
Go
2,289
Maven
5,000+
npm
3,936
NuGet
708
pip
3,706
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,034 advisories
Filter by severity
CMS Made Simple v2.2.15 was discovered to contain a Remote Command Execution (RCE) vulnerability...
High
Unreviewed
CVE-2022-23906
was published
Mar 2, 2022
A Remote Code Execution (RCE) vulnerabilty exists in LimeSurvey 5.2.4 via the upload and install...
High
Unreviewed
CVE-2021-44967
was published
Feb 25, 2022
WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged...
High
Unreviewed
CVE-2022-25360
was published
Feb 25, 2022
An Authenticated Remote Code Exection (RCE) vulnerability exists in Xerte through 3.9 in...
High
Unreviewed
CVE-2021-44664
was published
Feb 25, 2022
WikiDocs version 0.1.18 has an authenticated remote code execution vulnerability. An attacker can...
High
Unreviewed
CVE-2022-23375
was published
Feb 20, 2022
Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in...
High
Unreviewed
CVE-2022-23048
was published
Feb 11, 2022
The config restore function of Voipmonitor GUI before v24.96 does not properly check files sent...
High
Unreviewed
CVE-2022-24262
was published
Feb 10, 2022
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP...
High
Unreviewed
CVE-2022-24676
was published
Feb 10, 2022
Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote...
High
Unreviewed
CVE-2021-46360
was published
Feb 10, 2022
A vulnerability has been identified in COMOS V10.2 (All versions only if web components are used)...
High
Unreviewed
CVE-2021-37194
was published
Feb 10, 2022
Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php...
High
Unreviewed
CVE-2021-46097
was published
Jan 28, 2022
SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability,...
High
Unreviewed
CVE-2021-44123
was published
Jan 27, 2022
jpress 4.2.0 is vulnerable to RCE via io.jpress.web.admin._TemplateController#doUploadFile. The...
High
Unreviewed
CVE-2021-46115
was published
Jan 27, 2022
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.web.admin._TemplateController...
High
Unreviewed
CVE-2021-46116
was published
Jan 27, 2022
In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution...
High
Unreviewed
CVE-2021-46113
was published
Jan 26, 2022
jpress v4.2.0 allows users to register an account by default. With the account, user can upload...
High
Unreviewed
CVE-2021-45808
was published
Jan 20, 2022
Leostream Connection Broker 9.0.40.17 allows administrator to upload and execute Perl code.
High
Unreviewed
CVE-2021-41550
was published
Jan 19, 2022
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by...
High
Unreviewed
CVE-2021-33828
was published
Jan 16, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2021-34995
was published
Jan 14, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2021-34997
was published
Jan 14, 2022
Zoho ManageEngine CloudSecurityPlus before Build 4117 allows remote code execution through the...
High
Unreviewed
CVE-2021-44651
was published
Jan 13, 2022
An unrestricted file upload vulnerability in /UploadPsIcon.jsp in SysAid ITIL 20.4.74 b10 allows...
High
Unreviewed
CVE-2021-43973
was published
Jan 12, 2022
Sourcecodester Vehicle Service Management System 1.0 is vulnerable to File upload. An attacker...
High
Unreviewed
CVE-2021-46076
was published
Jan 7, 2022
An Unrestricted File Upload vulnerability exists in Sourcecodester Vehicle Service Management...
High
Unreviewed
CVE-2021-46079
was published
Jan 7, 2022
The "Log alert to a file" action within action management enables any Orion Platform user with...
High
Unreviewed
CVE-2021-35244
was published
Dec 21, 2021
ProTip!
Advisories are also available from the
GraphQL API