GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,741
NuGet
668
pip
3,422
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
20,944 advisories
Filter by severity
Incorrect Privilege Assignment vulnerability in VibeThemes WPLMS allows Privilege Escalation.This...
Critical
Unreviewed
CVE-2024-56043
was published
Dec 31, 2024
Path Traversal: '.../...//' vulnerability in VibeThemes WPLMS allows Path Traversal.This issue...
Critical
Unreviewed
CVE-2024-56045
was published
Dec 31, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS allows Upload a...
Critical
Unreviewed
CVE-2024-56046
was published
Dec 31, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56042
was published
Dec 31, 2024
Incorrect Privilege Assignment vulnerability in VibeThemes VibeBP allows Privilege Escalation...
Critical
Unreviewed
CVE-2024-56040
was published
Dec 31, 2024
Authentication Bypass Using an Alternate Path or Channel vulnerability in VibeThemes WPLMS allows...
Critical
Unreviewed
CVE-2024-56044
was published
Dec 31, 2024
Incorrect Privilege Assignment vulnerability in AI Magic allows Privilege Escalation.This issue...
Critical
Unreviewed
CVE-2024-56205
was published
Dec 31, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in Azzaroco WP SuperBackup allows...
Critical
Unreviewed
CVE-2024-56064
was published
Dec 31, 2024
Incorrect Privilege Assignment vulnerability in Mike Leembruggen Simple Dashboard allows...
Critical
Unreviewed
CVE-2024-56071
was published
Dec 31, 2024
Missing Authorization vulnerability in Inspry Agency Toolkit allows Privilege Escalation.This...
Critical
Unreviewed
CVE-2024-56066
was published
Dec 31, 2024
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2024-56039
was published
Dec 31, 2024
The Electronic Official Document Management System from 2100 Technology has an Authentication...
Critical
Unreviewed
CVE-2024-13061
was published
Dec 31, 2024
In WhatsUp Gold versions released before 2024.0.2, an attacker can gain access to the WhatsUp...
Critical
Unreviewed
CVE-2024-12108
was published
Dec 31, 2024
In WhatsUp Gold versions released before 2024.0.2, an unauthenticated attacker can configure LDAP...
Critical
Unreviewed
CVE-2024-12106
was published
Dec 31, 2024
Incorrect Privilege Assignment vulnerability in SSL Wireless SSL Wireless SMS Notification allows...
Critical
Unreviewed
CVE-2024-56220
was published
Dec 31, 2024
The Hunk Companion WordPress plugin before 1.9.0 does not correctly authorize some REST API...
Critical
Unreviewed
CVE-2024-11972
was published
Dec 31, 2024
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows...
Critical
Unreviewed
CVE-2024-12828
was published
Dec 30, 2024
A Server-Side Request Forgery (SSRF) vulnerability exists in the POST /worker_generate_stream API...
Critical
Unreviewed
CVE-2024-10044
was published
Dec 30, 2024
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS...
Critical
Unreviewed
CVE-2024-47919
was published
Dec 30, 2024
Tecnick TCExam – CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL...
Critical
Unreviewed
CVE-2024-47926
was published
Dec 30, 2024
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50717
was published
Dec 27, 2024
SQL injection vulnerability in Smart Agent v.1.1.0 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-50716
was published
Dec 27, 2024
SmartAgent v1.1.0 was discovered to contain a SQL injection vulnerability via the id parameter at...
Critical
Unreviewed
CVE-2024-50713
was published
Dec 27, 2024
Integer overflow vulnerability exists in SimplCommerce at commit...
Critical
Unreviewed
CVE-2024-50944
was published
Dec 27, 2024
An issue was discovered in Kurmi Provisioning Suite 7.9.0.33. If an X-Forwarded-For header is...
Critical
Unreviewed
CVE-2024-54450
was published
Dec 27, 2024
ProTip!
Advisories are also available from the
GraphQL API