GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
113,186 advisories
Filter by severity
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via app\admin\firewall-zones\zones-edit...
Moderate
Unreviewed
CVE-2024-41356
was published
Jul 26, 2024
phpipam 1.6 is vulnerable to Cross Site Scripting (XSS) via /app/tools/request-ip/index.php.
Moderate
Unreviewed
CVE-2024-41355
was published
Jul 26, 2024
IBM InfoSphere Information Server 11.7 is vulnerable to SQL injection. A remote attacker could...
Moderate
Unreviewed
CVE-2024-40689
was published
Jul 26, 2024
Automation Anywhere Automation 360 v21-v32 is vulnerable to Server-Side Request Forgery in a web...
Moderate
Unreviewed
CVE-2024-6922
was published
Jul 26, 2024
A flaw was found in the Openshift console. Several endpoints in the application use the...
Moderate
Unreviewed
CVE-2024-7128
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to unencrypted storing of WPA...
Moderate
Unreviewed
CVE-2024-41689
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing HTTPOnly flag for...
Moderate
Unreviewed
CVE-2024-41685
was published
Jul 26, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for...
Moderate
Unreviewed
CVE-2024-41684
was published
Jul 26, 2024
Insufficient input validation and sanitation in Profile name & screenname, Bookmark name &...
Moderate
Unreviewed
CVE-2024-25090
was published
Jul 26, 2024
During testing of the Master Slider WordPress plugin through 3.9.10, a CSRF vulnerability was...
Moderate
Unreviewed
CVE-2024-6490
was published
Jul 26, 2024
A vulnerability, which was classified as critical, was found in Raisecom MSG1200, MSG2100E,...
Moderate
Unreviewed
CVE-2024-7120
was published
Jul 26, 2024
A vulnerability, which was classified as critical, has been found in MD-MAFUJUL-HASAN Online...
Moderate
Unreviewed
CVE-2024-7119
was published
Jul 26, 2024
A vulnerability classified as critical was found in MD-MAFUJUL-HASAN Online-Payroll-Management...
Moderate
Unreviewed
CVE-2024-7118
was published
Jul 26, 2024
A vulnerability classified as critical has been found in MD-MAFUJUL-HASAN Online-Payroll...
Moderate
Unreviewed
CVE-2024-7117
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7115
was published
Jul 26, 2024
A vulnerability was found in MD-MAFUJUL-HASAN Online-Payroll-Management-System up to 20230911. It...
Moderate
Unreviewed
CVE-2024-7116
was published
Jul 26, 2024
A vulnerability was found in Tianchoy Blog up to 1.8.8. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2024-7114
was published
Jul 26, 2024
In the System → Maintenance tool, the Logged Users tab surfaces sessionId data for all users via...
Moderate
Unreviewed
CVE-2024-4447
was published
Jul 26, 2024
The "reset password" login page accepted an HTML injection via URL parameters.
This has already...
Moderate
Unreviewed
CVE-2024-3938
was published
Jul 26, 2024
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-38103
was published
Jul 26, 2024
A vulnerability classified as critical has been found in ForIP Tecnologia Administração PABX 1.x....
Moderate
Unreviewed
CVE-2024-7105
was published
Jul 25, 2024
HMS Industrial Networks
Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by...
Moderate
Unreviewed
CVE-2024-6558
was published
Jul 25, 2024
There is a cross-site scripting vulnerability in the Secure
Access administrative console of...
Moderate
Unreviewed
CVE-2024-40873
was published
Jul 25, 2024
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 uses...
Moderate
Unreviewed
CVE-2022-32759
was published
Jul 25, 2024
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 is...
Moderate
Unreviewed
CVE-2024-28772
was published
Jul 25, 2024
ProTip!
Advisories are also available from the
GraphQL API