GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
267 advisories
Filter by severity
The Front End PM WordPress plugin before 11.4.3 does not block listing the contents of the...
Moderate
Unreviewed
CVE-2023-4930
was published
Nov 6, 2023
Incorrect access to deleted scripts vulnerability in McAfee Database Security (DBSec) prior to 4...
High
Unreviewed
CVE-2021-31831
was published
May 24, 2022
Local Temp Directory Hijacking Vulnerability
High
CVE-2020-27216
was published
for
org.eclipse.jetty:jetty-webapp
(Maven)
Nov 4, 2020
CLUSTERPRO X Ver5.1 and earlier and EXPRESSCLUSTER X 5.1 and earlier, CLUSTERPRO X...
High
Unreviewed
CVE-2023-39545
was published
Nov 17, 2023
Tyler Technologies Court Case Management Plus may store backups in a location that can be...
Moderate
Unreviewed
CVE-2023-6375
was published
Nov 30, 2023
Dell vApp Manager, versions prior to 9.2.4.x contain an arbitrary file read vulnerability. A...
Moderate
Unreviewed
CVE-2023-48661
was published
Dec 14, 2023
Apache Struts vulnerable to path traversal
Critical
CVE-2023-50164
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 7, 2023
The File Manager WordPress plugin before 6.3 does not restrict the file managers root directory,...
Moderate
Unreviewed
CVE-2023-5907
was published
Dec 11, 2023
The Duplicator WordPress plugin before 1.5.7.1, Duplicator Pro WordPress plugin before 4.5.14.2...
High
Unreviewed
CVE-2023-6114
was published
Dec 26, 2023
The Backup Migration plugin for WordPress is vulnerable to unauthorized access of data due to...
High
Unreviewed
CVE-2023-6266
was published
Jan 11, 2024
NEXTWEB (i)Site stores databases under the web document root with insufficient access control,...
Moderate
Unreviewed
CVE-2005-1835
was published
May 1, 2022
Digitaldesign CMS 0.1 stores sensitive information under the web root with insufficient access...
Moderate
Unreviewed
CVE-2009-3597
was published
May 2, 2022
Unauthorized file access vulnerability in the wallpaper service module. Successful exploitation...
Moderate
Unreviewed
CVE-2023-52112
was published
Jan 16, 2024
A vulnerability has been found in Shanxi Diankeyun Technology NODERP up to 6.0.2 and classified...
Moderate
Unreviewed
CVE-2024-1005
was published
Jan 29, 2024
Broken access control on files
Moderate
CVE-2019-14273
was published
for
silverstripe/framework
(Composer)
Jul 15, 2020
Unrestricted File Upload in Form Framework
High
CVE-2021-21355
was published
for
typo3/cms
(Composer)
Mar 23, 2021
A vulnerability in the on-device application development workflow feature for the Cisco IOx...
High
Unreviewed
CVE-2023-20235
was published
Oct 4, 2023
Dompdf allows remote file inclusion because URI validation failure does not halt font registration
High
CVE-2022-41343
was published
for
dompdf/dompdf
(Composer)
Sep 26, 2022
Guava vulnerable to insecure use of temporary directory
Moderate
CVE-2023-2976
was published
for
com.google.guava:guava
(Maven)
Jun 14, 2023
Improper Input Validation, Files or Directories Accessible to External Parties vulnerability in...
High
Unreviewed
CVE-2023-4550
was published
Jan 29, 2024
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming...
High
Unreviewed
CVE-2024-24161
was published
Feb 2, 2024
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with...
Moderate
Unreviewed
CVE-2024-22240
was published
Feb 6, 2024
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the...
Moderate
Unreviewed
CVE-2023-4933
was published
Oct 16, 2023
A CWE-552 “Files or Directories Accessible to External Parties” vulnerability in the embedded...
Moderate
Unreviewed
CVE-2023-45594
was published
Mar 5, 2024
Files or Directories Accessible to External Parties in org.springframework:spring-core
High
CVE-2015-5211
was published
for
org.springframework:spring-core
(Maven)
Oct 17, 2018
ProTip!
Advisories are also available from the
GraphQL API