GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
16 advisories
Filter by severity
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')...
Unknown
Unreviewed
CVE-2024-13265
was published
Jan 9, 2025
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')...
Critical
Unreviewed
CVE-2024-13264
was published
Jan 9, 2025
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')...
Unknown
Unreviewed
CVE-2024-13267
was published
Jan 9, 2025
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')...
Unknown
Unreviewed
CVE-2024-13268
was published
Jan 9, 2025
Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection')...
Moderate
Unreviewed
CVE-2024-13263
was published
Jan 9, 2025
XWiki allows remote code execution through the extension sheet
Critical
CVE-2024-55662
was published
for
org.xwiki.platform:xwiki-platform-repository-server-ui
(Maven)
Dec 12, 2024
XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
Critical
CVE-2024-55877
was published
for
org.xwiki.platform:xwiki-platform-help-ui
(Maven)
Dec 12, 2024
XWiki Platform allows XSS through XClass name in string properties
Critical
CVE-2024-43400
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Aug 19, 2024
XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
High
CVE-2024-37900
was published
for
org.xwiki.platform:xwiki-platform-web-war
(Maven)
Jul 31, 2024
less through 653 allows OS command execution via a newline character in the name of a file,...
High
Unreviewed
CVE-2024-32487
was published
Apr 13, 2024
SUPERAntiSpyware Pro X v10.0.1260 is vulnerable to kernel-level API parameters manipulation and...
Moderate
Unreviewed
CVE-2024-0788
was published
Jan 29, 2024
An issue in Mintty v.3.6.4 and before allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2023-39726
was published
Oct 26, 2023
Froxlor contains Static Code Injection
Moderate
CVE-2023-0566
was published
for
froxlor/froxlor
(Composer)
Jan 30, 2023
Path Traversal in django-s3file
Critical
CVE-2022-24840
was published
for
django-s3file
(pip)
Jun 6, 2022
Affected versions of Atlassian Jira Service Management Server and Data Center allow remote...
High
Unreviewed
CVE-2021-39115
was published
May 24, 2022
Static Code Injection in Microweber
High
CVE-2022-0895
was published
for
microweber/microweber
(Composer)
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API