GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
70 advisories
Filter by severity
Markdownify subject to Remote Code Execution via malicious markdown file
High
CVE-2022-41709
was published
for
electron-markdownify
(npm)
Oct 19, 2022
A vulnerability in the custom URL parser of Cisco Webex App could allow an unauthenticated,...
High
Unreviewed
CVE-2025-20236
was published
Apr 16, 2025
An iframe that was not permitted to run scripts could do so if the user clicked on a <code...
High
Unreviewed
CVE-2022-34468
was published
Dec 22, 2022
An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B...
High
Unreviewed
CVE-2024-45482
was published
Mar 25, 2025
Kedro allows Remote Code Execution by Pulling Micro Packages
High
CVE-2024-12215
was published
for
kedro
(pip)
Mar 20, 2025
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin...
High
Unreviewed
CVE-2024-13353
was published
Feb 21, 2025
Apache HDFS Provider error message suggested
High
CVE-2023-41267
was published
for
apache-airflow-providers-apache-hdfs
(pip)
Sep 14, 2023
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
High
CVE-2024-28184
was published
for
weasyprint
(pip)
Mar 8, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-53800
was published
Jan 7, 2025
An issue was discovered in the Webmail Classic UI in Zimbra Collaboration (ZCS) 9.0 and 10.0 and...
High
Unreviewed
CVE-2024-54663
was published
Dec 20, 2024
The install() function of ProviderInstaller.java in Magisk App before canary version 27007 does...
High
Unreviewed
CVE-2024-48336
was published
Nov 4, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-50497
was published
Oct 28, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49243
was published
Oct 18, 2024
Inclusion of functionality from untrusted control sphere vulnerability in OpenSSL DLL component...
High
Unreviewed
CVE-2022-49038
was published
Sep 26, 2024
The HTTPD binary in multiple ZTE routers has a local file inclusion vulnerability in session_init...
High
Unreviewed
CVE-2024-45416
was published
Sep 16, 2024
Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server...
High
Unreviewed
CVE-2024-43690
was published
Sep 11, 2024
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2024-8252
was published
Aug 30, 2024
Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and...
High
Unreviewed
CVE-2023-5523
was published
Oct 20, 2023
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5762
was published
Aug 21, 2024
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the...
High
Unreviewed
CVE-2021-41037
was published
Jul 9, 2022
An unauthenticated IEEE 802.15.4 'co-ordinator realignment' packet can be used to force Zigbee...
High
Unreviewed
CVE-2024-3043
was published
Jun 27, 2024
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
High
CVE-2021-20187
was published
for
moodle/moodle
(Composer)
May 24, 2022
Drupal Remote code execution
High
CVE-2017-6381
was published
for
drupal/core
(Composer)
May 13, 2022
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49133
was published
Apr 9, 2024
A command execution vulnerability exists in the tddpd enable_test_mode functionality of Tp-Link...
High
Unreviewed
CVE-2023-49134
was published
Apr 9, 2024
ProTip!
Advisories are also available from the
GraphQL API