GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
10,785 advisories
Filter by severity
Apache Zeppelin: Cron arbitrary user impersonation with improper privileges
Moderate
CVE-2024-31865
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
Apache Zeppelin: LDAP search filter query Injection Vulnerability
Moderate
CVE-2024-31867
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
Apache Pulsar: Improper Input Validation in Pulsar Function Worker allows Remote Code Execution
High
CVE-2024-27135
was published
for
org.apache.pulsar:pulsar-functions-worker
(Maven)
Mar 12, 2024
Apache Zeppelin: Denial of service with invalid notebook name
Moderate
CVE-2024-31862
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
Unified Automation UaGateway OPC UA Server Improper Input Validation Denial-of-Service...
Moderate
Unreviewed
CVE-2023-32170
was published
May 3, 2024
LG Simple Editor joinAddUser Improper Input Validation Denial-of-Service Vulnerability. This...
High
Unreviewed
CVE-2023-40515
was published
May 3, 2024
In preloader, there is a possible escalation of privilege due to an insecure default value. This...
Unknown
Unreviewed
CVE-2024-20056
was published
May 6, 2024
In wlan service, there is a possible out of bounds write due to improper input validation. This...
Unknown
Unreviewed
CVE-2024-20064
was published
May 6, 2024
A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0...
High
Unreviewed
CVE-2019-10190
was published
May 24, 2022
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows...
High
Unreviewed
CVE-2024-4040
was published
Apr 22, 2024
A SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe...
Critical
Unreviewed
CVE-2024-4547
was published
May 6, 2024
An SQLi vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior when CEBC.exe...
Critical
Unreviewed
CVE-2024-4548
was published
May 6, 2024
An improper authorization level has been detected in the login panel. It may lead to...
Moderate
Unreviewed
CVE-2023-7240
was published
May 7, 2024
Local Root Exploit via Configuration Dictionary in dnf5daemon-server before 5.1.17 allows a...
High
Unreviewed
CVE-2024-1929
was published
May 8, 2024
Incomplete fix for CVE-2024-1929
The problem with CVE-2024-1929 was that the dnf5 D-Bus daemon...
High
Unreviewed
CVE-2024-2746
was published
May 8, 2024
Apache Zeppelin Path Traversal vulnerability
Moderate
CVE-2024-31860
was published
for
org.apache.zeppelin:zeppelin-server
(Maven)
Apr 9, 2024
A Segmentation Fault issue discovered in
Samsung Open Source Escargot JavaScript engine
...
Moderate
Unreviewed
CVE-2024-32672
was published
May 14, 2024
Insufficient verification vulnerability in the baseband module
Impact: Successful exploitation of...
High
Unreviewed
CVE-2024-32992
was published
May 14, 2024
Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation...
Moderate
Unreviewed
CVE-2024-25970
was published
May 14, 2024
Improper validation of certain metadata input may result in the server not correctly serialising...
High
Unreviewed
CVE-2024-3372
was published
May 14, 2024
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Moderate
Unreviewed
CVE-2024-29998
was published
May 14, 2024
Windows Mobile Broadband Driver Remote Code Execution Vulnerability
Moderate
Unreviewed
CVE-2024-30002
was published
May 14, 2024
Windows MSHTML Platform Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-30040
was published
May 14, 2024
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input...
High
Unreviewed
CVE-2024-3676
was published
May 14, 2024
Apache Karaf Cave: Cave SSRF and arbitrary file access
Critical
CVE-2024-34365
was published
for
org.apache.karaf:cave
(Maven)
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API