GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
89 advisories
Filter by severity
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
Mesop Class Pollution vulnerability leads to DoS and Jailbreak attacks
High
CVE-2025-30358
was published
for
mesop
(pip)
Mar 27, 2025
In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation...
Moderate
Unreviewed
CVE-2024-10359
was published
Mar 20, 2025
Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment
Critical
CVE-2025-2304
was published
for
camaleon_cms
(RubyGems)
Mar 14, 2025
Django-Unicorn Class Pollution Vulnerability, Leading to XSS, DoS and Authentication Bypass
Critical
CVE-2025-24370
was published
for
django-unicorn
(pip)
Feb 3, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
Drupal core contains a potential PHP Object Injection vulnerability
Low
CVE-2024-55636
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55638
was published
for
drupal/core
(Composer)
Dec 10, 2024
Drupal core contains a potential PHP Object Injection vulnerability
High
CVE-2024-55637
was published
for
drupal/core
(Composer)
Dec 10, 2024
Remote code execution in pytorch lightning
Critical
CVE-2024-5452
was published
for
lightning
(pip)
Jun 6, 2024
A mass assignment vulnerability exists in the `/api/invite/:code` endpoint of the mintplex-labs...
Critical
Unreviewed
CVE-2024-0404
was published
Apr 16, 2024
A vulnerability in mintplex-labs/anything-llm allows users with manager roles to escalate their...
High
Unreviewed
CVE-2024-3283
was published
Apr 10, 2024
A vulnerability that poses a potential risk of polluting the MXsecurity sqlite database and the...
Moderate
Unreviewed
CVE-2023-39983
was published
Sep 2, 2023
Netmaker Vulnerable to Privilege Escalation From Non Admin To Admin User
High
CVE-2023-32079
was published
for
github.com/gravitl/netmaker
(Go)
Aug 25, 2023
The recovery mode for updates has a vulnerability that causes arbitrary disk modification....
High
Unreviewed
CVE-2022-48359
was published
Mar 28, 2023
sqlite vulnerable to code execution due to Object coercion
High
CVE-2022-43441
was published
for
sqlite3
(npm)
Mar 13, 2023
A vulnerability found in postgresql. On this security issue an attack requires permission to...
High
Unreviewed
CVE-2022-2625
was published
Aug 19, 2022
qcubed PHP object injection
Critical
CVE-2020-24914
was published
for
qcubed/qcubed
(Composer)
May 24, 2022
PHP object injection in the Ajax endpoint of the backend in ForkCMS below version 5.8.3 allows an...
High
Unreviewed
CVE-2020-24036
was published
May 24, 2022
The Cloud Functions subsystem in OpenTrace 1.0 might allow fabrication attacks by making billions...
Moderate
Unreviewed
CVE-2020-11872
was published
May 24, 2022
An issue was discovered in CMS Made Simple 2.2.8. In the administrator page admin/changegroupperm...
High
Unreviewed
CVE-2019-9058
was published
May 13, 2022
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images)...
High
Unreviewed
CVE-2018-6195
was published
May 13, 2022
The script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318...
High
Unreviewed
CVE-2018-11135
was published
May 13, 2022
Prototype Pollution in deepmerge-ts
High
CVE-2022-24802
was published
for
deepmerge-ts
(npm)
Apr 1, 2022
ProTip!
Advisories are also available from the
GraphQL API