GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,077
Erlang
29
GitHub Actions
19
Go
1,903
Maven
5,000+
npm
3,632
NuGet
638
pip
3,249
Pub
10
RubyGems
864
Rust
818
Swift
35
Unreviewed advisories
All unreviewed
5,000+
122 advisories
Filter by severity
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user...
High
Unreviewed
CVE-2023-0331
was published
Feb 27, 2023
CRMEB 4.4.4 is vulnerable to Any File download.
High
Unreviewed
CVE-2022-44343
was published
Feb 6, 2023
Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the...
High
Unreviewed
CVE-2022-48161
was published
Feb 1, 2023
redhat-certification does not properly restrict files that can be download through the /download...
High
Unreviewed
CVE-2018-10869
was published
May 13, 2022
A flaw was found in ansible-tower where the default installation is vulnerable to job isolation...
High
Unreviewed
CVE-2021-4112
was published
Aug 26, 2022
A vulnerability was found in fapolicyd. The vulnerability occurs due to an assumption on how...
High
Unreviewed
CVE-2022-1117
was published
Aug 29, 2022
Information Exposure in Heketi
High
CVE-2017-15104
was published
for
github.com/heketi/heketi
(Go)
Feb 15, 2022
Archeevo below 5.0 is affected by local file inclusion through file=~/web.config to allow an...
High
Unreviewed
CVE-2022-23377
was published
Mar 2, 2022
This affects the package drogonframework/drogon before 1.7.5. The unsafe handling of file names...
High
Unreviewed
CVE-2022-25297
was published
Feb 22, 2022
HorizontCMS v1.0.0-beta.2 was discovered to contain an arbitrary file download vulnerability via...
High
Unreviewed
CVE-2022-25104
was published
Feb 25, 2022
This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during...
High
Unreviewed
CVE-2022-25299
was published
Feb 19, 2022
An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary...
High
Unreviewed
CVE-2022-0244
was published
Jan 19, 2022
Vulnerability in Wordpress plugin BackWPup before v3.4.2 allows possible brute forcing of backup...
High
Unreviewed
CVE-2017-2551
was published
May 17, 2022
In savePhotoFromUriToUri of ContactPhotoUtils.java in Android-7.0, Android-7.1.1, Android-7.1.2,...
High
Unreviewed
CVE-2018-9587
was published
May 13, 2022
Development Tools panels of an extension are required to load URLs for the panels as relative...
High
Unreviewed
CVE-2018-5112
was published
May 13, 2022
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers...
High
Unreviewed
CVE-2018-16946
was published
May 13, 2022
The Welcart e-Commerce WordPress plugin before 2.8.5 does not validate user input before using it...
High
Unreviewed
CVE-2022-4140
was published
Jan 3, 2023
Tenshi 0.15 creates a tenshi.pid file after dropping privileges to a non-root account, which...
High
Unreviewed
CVE-2017-11746
was published
May 13, 2022
Files or Directories Accessible to External Parties in kubernetes
High
CVE-2021-25741
was published
for
k8s.io/kubernetes
(Go)
Nov 1, 2021
Files or Directories Accessible to External Parties in ether/logs
High
CVE-2021-32752
was published
for
ether/logs
(Composer)
Jul 12, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket
High
CVE-2020-11976
was published
for
org.apache.wicket:wicket-core
(Maven)
May 7, 2021
Unauth. Arbitrary File Download vulnerability in WatchTowerHQ plugin <= 3.6.15 on WordPress.
High
Unreviewed
CVE-2022-44583
was published
Nov 19, 2022
Roundcube Webmail before 1.1.10, 1.2.x before 1.2.7, and 1.3.x before 1.3.3 allows unauthorized...
High
Unreviewed
CVE-2017-16651
was published
May 13, 2022
The WSM Downloader WordPress plugin through 1.4.0 allows any visitor to use its remote file...
High
Unreviewed
CVE-2022-2357
was published
Aug 9, 2022
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
High
Unreviewed
CVE-2022-28462
was published
May 6, 2022
ProTip!
Advisories are also available from the
GraphQL API