GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,978
Erlang
29
GitHub Actions
16
Go
1,768
Maven
4,991
npm
3,537
NuGet
616
pip
3,107
Pub
10
RubyGems
837
Rust
786
Swift
34
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
370 advisories
Filter by severity
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5_2, 6.0.0.0 through 6.0.3.2,...
High
Unreviewed
CVE-2019-4728
was published
May 24, 2022
The fileop module of the NXLog service in NXLog Community Edition 2.10.2150 allows remote...
High
Unreviewed
CVE-2020-35488
was published
May 24, 2022
The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file,...
High
Unreviewed
CVE-2022-3417
was published
Jan 10, 2023
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute...
High
Unreviewed
CVE-2020-4589
was published
May 24, 2022
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an...
High
Unreviewed
CVE-2022-3679
was published
Jan 10, 2023
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to achieve...
High
Unreviewed
CVE-2020-14172
was published
May 24, 2022
The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via...
High
Unreviewed
CVE-2022-4043
was published
Jan 10, 2023
Auth. (subscriber+) PHP Object Injection vulnerability in Betheme theme <= 26.5.1.4 on WordPress.
High
Unreviewed
CVE-2022-45077
was published
Nov 18, 2022
The Apros Evolution, ConsciusMap, and Furukawa provisioning systems through 2.8.1 allow remote...
High
Unreviewed
CVE-2020-12133
was published
May 24, 2022
A vulnerability has been identified in SPPA-T3000 Application Server (All versions). The...
High
Unreviewed
CVE-2019-18283
was published
May 24, 2022
A flaw was found in the yaml.load() function in the osbs-client versions since 0.46 before 0.56.1...
High
Unreviewed
CVE-2019-10135
was published
May 24, 2022
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and...
High
Unreviewed
CVE-2022-1118
was published
May 18, 2022
An issue was discovered in CMS Made Simple 2.2.8. In the module ModuleManager (in the file action...
High
Unreviewed
CVE-2019-9061
was published
May 13, 2022
An issue was discovered in CMS Made Simple 2.2.8. In the module FilePicker, it is possible to...
High
Unreviewed
CVE-2019-9057
was published
May 13, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2022-35872
was published
Jul 26, 2022
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote...
High
Unreviewed
CVE-2016-7065
was published
May 17, 2022
The Ninja Forms Contact Form WordPress plugin before 3.6.13 unserialises the content of an...
High
Unreviewed
CVE-2022-2903
was published
Sep 27, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of...
High
Unreviewed
CVE-2022-35870
was published
Jul 26, 2022
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior...
High
Unreviewed
CVE-2022-33315
was published
Jul 21, 2022
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior...
High
Unreviewed
CVE-2022-33316
was published
Jul 21, 2022
This issue affects: HYPR Windows WFA versions prior to 7.2; Unsafe Deserialization vulnerability...
High
Unreviewed
CVE-2022-1984
was published
Jul 20, 2022
A deserialization vulnerability in a .NET framework class used and not properly checked by Safety...
High
Unreviewed
CVE-2022-27580
was published
Jul 20, 2022
A deserialization vulnerability in a .NET framework class used and not properly checked by Flexi...
High
Unreviewed
CVE-2022-27579
was published
Jul 20, 2022
An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local...
High
Unreviewed
CVE-2021-36665
was published
Jul 13, 2022
An issue was discovered in Gentics CMS before 5.43.1. By uploading a malicious ZIP file, an...
High
Unreviewed
CVE-2022-30981
was published
Jul 18, 2022
ProTip!
Advisories are also available from the
GraphQL API