GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
10,719 advisories
Filter by severity
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
High
Unreviewed
CVE-2024-6333
was published
Oct 17, 2024
On Microchip RN4870 devices, when more than one consecutive PairReqNoInputNoOutput request is ...
Moderate
Unreviewed
CVE-2024-29155
was published
Oct 16, 2024
Docker Desktop before v4.34.3 allows RCE via unsanitized GitHub source link in Build view.
High
Unreviewed
CVE-2024-9348
was published
Oct 16, 2024
Account users in Apache CloudStack by default are allowed to upload and register templates for...
High
Unreviewed
CVE-2024-45219
was published
Oct 16, 2024
Vendure asset server plugin has local file read vulnerability with AssetServerPlugin & LocalAssetStorageStrategy
Critical
CVE-2024-48914
was published
for
@vendure/asset-server-plugin
(npm)
Oct 15, 2024
An unauthenticated local attacker can gain admin privileges by deploying a config file due to...
High
Unreviewed
CVE-2024-45271
was published
Oct 15, 2024
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory...
High
Unreviewed
CVE-2024-6207
was published
Oct 14, 2024
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS...
High
Unreviewed
CVE-2024-8755
was published
Oct 11, 2024
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form &...
Moderate
Unreviewed
CVE-2024-9507
was published
Oct 11, 2024
Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version...
Moderate
Unreviewed
CVE-2023-24463
was published
Oct 10, 2024
Magento Open Source Improper Input Validation vulnerability
Moderate
CVE-2024-45117
was published
for
magento/community-edition
(Composer)
Oct 10, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), Improper...
High
Unreviewed
CVE-2024-9286
was published
Oct 9, 2024
Livewire Remote Code Execution on File Uploads
High
CVE-2024-47823
was published
for
livewire/livewire
(Composer)
Oct 8, 2024
Windows Hyper-V Security Feature Bypass Vulnerability
High
Unreviewed
CVE-2024-20659
was published
Oct 8, 2024
Windows Hyper-V Remote Code Execution Vulnerability
High
Unreviewed
CVE-2024-30092
was published
Oct 8, 2024
CWE-20: Improper Input Validation vulnerability exists that could cause a crash of the Zelio Soft...
Low
Unreviewed
CVE-2024-8518
was published
Oct 8, 2024
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
Low
Unreviewed
CVE-2024-43697
was published
Oct 8, 2024
Memory corruption while taking snapshot when an offset variable is set by camera driver.
High
Unreviewed
CVE-2024-33065
was published
Oct 7, 2024
Memory corruption while redirecting log file to any file location with any file name.
Critical
Unreviewed
CVE-2024-33066
was published
Oct 7, 2024
In Modem, there is a possible system crash due to a missing bounds check. This could lead to...
High
Unreviewed
CVE-2024-20094
was published
Oct 7, 2024
Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of...
Moderate
Unreviewed
CVE-2024-45871
was published
Oct 3, 2024
An attacker can publish a zone containing specific Resource Record Sets.
Repeatedly processing...
High
Unreviewed
CVE-2024-25590
was published
Oct 3, 2024
Improper Input Validation in Buildah and Podman
Moderate
CVE-2024-9407
was published
for
github.com/containers/buildah
(Go)
Oct 1, 2024
An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could...
High
Unreviewed
CVE-2024-6436
was published
Sep 27, 2024
A vulnerability in the Protocol Independent Multicast (PIM) feature of Cisco IOS XE Software...
High
Unreviewed
CVE-2024-20464
was published
Sep 25, 2024
ProTip!
Advisories are also available from the
GraphQL API