GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
37
Go
2,526
Maven
5,000+
npm
4,189
NuGet
742
pip
3,968
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
236 advisories
Filter by severity
The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.
Critical
Unreviewed
CVE-2017-18583
was published
May 24, 2022
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as...
Critical
Unreviewed
CVE-2019-12966
was published
May 24, 2022
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules...
Critical
Unreviewed
CVE-2016-8900
was published
May 24, 2022
b2evolution 6.7.6 suffer from an Object Injection vulnerability in /htsrv/call_plugin.php.
Critical
Unreviewed
CVE-2016-8901
was published
May 24, 2022
Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules...
Critical
Unreviewed
CVE-2016-8899
was published
May 24, 2022
eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data
Critical
Unreviewed
CVE-2014-3700
was published
May 17, 2022
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote...
Critical
Unreviewed
CVE-2013-7070
was published
May 5, 2022
The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP...
Critical
Unreviewed
CVE-2011-2717
was published
Apr 22, 2022
** DISPUTED ** An issue was discovered in SMA Solar Technology products. The SIP implementation...
Critical
Unreviewed
CVE-2017-9861
was published
May 17, 2022
** DISPUTED ** Elasticsearch before 1.6.1 allows remote attackers to execute arbitrary code via...
Critical
Unreviewed
CVE-2015-5377
was published
May 14, 2022
ejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable,...
Critical
Unreviewed
CVE-2023-29827
was published
May 4, 2023
Server crashes on invalid Cloud Function or Cloud Job name
Critical
CVE-2024-29027
was published
for
parse-server
(npm)
Mar 19, 2024
TWiki allows arbitrary shell command execution via the Include function
Critical
Unreviewed
CVE-2005-3056
was published
Apr 21, 2022
Expression injection in AviatorScript
Critical
CVE-2021-41862
was published
for
com.googlecode.aviator:aviator
(Maven)
Oct 4, 2021
Remote code execution via vulnerable Symphony dependecy injection
Critical
CVE-2019-8135
was published
for
magento/community-edition
(Composer)
Nov 12, 2019
An issue in Jumpserver 2.6.2 and below allows attackers to create a connection token through an...
Critical
Unreviewed
CVE-2021-3169
was published
May 24, 2022
Remote Code Execution in SyliusResourceBundle
Critical
CVE-2020-15146
was published
for
sylius/resource-bundle
(Composer)
Aug 19, 2020
npm package rfc6902 vulnerable to Prototype Pollution
Critical
CVE-2021-4245
was published
for
rfc6902
(npm)
Dec 15, 2022
Apache Derby: LDAP injection vulnerability in authenticator
Critical
CVE-2022-46337
was published
for
org.apache.derby:derby
(Maven)
Nov 20, 2023
Intumit inc. SmartRobot's web framwork has a remote code execution vulnerability. An unauthorized...
Critical
Unreviewed
CVE-2024-0552
was published
Jan 15, 2024
A vulnerability has been found in Activity Log Plugin and classified as critical. This...
Critical
Unreviewed
CVE-2022-3941
was published
Nov 11, 2022
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell...
Critical
Unreviewed
CVE-2023-46456
was published
Dec 12, 2023
This Template Injection vulnerability allows an authenticated attacker, including one with...
Critical
Unreviewed
CVE-2023-22522
was published
Dec 6, 2023
HtmlUnit Code Injection vulnerability
Critical
CVE-2023-26119
was published
for
net.sourceforge.htmlunit:htmlunit
(Maven)
Jul 6, 2023
Usedesk before 1.7.57 allows chat template injection.
Critical
Unreviewed
CVE-2023-49214
was published
Nov 24, 2023
ProTip!
Advisories are also available from the
GraphQL API