GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
30,221 advisories
Filter by severity
DS Wireless Communication (DWC) with DWC_VERSION_3 and DWC_VERSION_11 allows remote attackers to...
Critical
Unreviewed
CVE-2023-45887
was published
Dec 20, 2023
EuroTel ETL3100 versions v01c01 and v01x37 does not limit the number of attempts to guess...
Critical
Unreviewed
CVE-2023-6928
was published
Dec 20, 2023
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard...
Critical
Unreviewed
CVE-2023-47267
was published
Dec 20, 2023
An issue in D-Link DIR-850L v.B1_FW223WWb01 allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-49004
was published
Dec 20, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-48738
was published
Dec 19, 2023
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2023-49750
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46224
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46258
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46220
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46221
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46225
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46261
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46222
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46257
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46259
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46223
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46216
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-46217
was published
Dec 19, 2023
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory...
Critical
Unreviewed
CVE-2023-41727
was published
Dec 19, 2023
transformers has a Deserialization of Untrusted Data vulnerability
Critical
CVE-2023-6730
was published
for
transformers
(pip)
Dec 19, 2023
Pedroetb TTS-API OS Command Injection
Critical
CVE-2019-25158
was published
for
tts-api
(npm)
Dec 19, 2023
The Theme My Login 2FA WordPress plugin before 1.2 does not rate limit 2FA validation attempts,...
Critical
Unreviewed
CVE-2023-6272
was published
Dec 18, 2023
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has...
Critical
Unreviewed
CVE-2023-51385
was published
Dec 18, 2023
Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the...
Critical
Unreviewed
CVE-2023-50976
was published
Dec 18, 2023
In MicroHttpServer (aka Micro HTTP Server) through 4398570, _ReadStaticFiles in lib/middleware.c...
Critical
Unreviewed
CVE-2023-50965
was published
Dec 17, 2023
ProTip!
Advisories are also available from the
GraphQL API