GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,968
Erlang
29
GitHub Actions
16
Go
1,749
Maven
4,978
npm
3,509
NuGet
609
pip
3,084
Pub
10
RubyGems
832
Rust
782
Swift
34
Unreviewed advisories
All unreviewed
5,000+
931 advisories
Filter by severity
HCL BigFix Mobile is vulnerable to a cross-site scripting attack. An authenticated attacker could...
High
Unreviewed
CVE-2023-28012
was published
Jul 27, 2023
Local user may lead to privilege escalation using Gaia Portal hostnames page.
High
Unreviewed
CVE-2023-28130
was published
Jul 26, 2023
Spring-boot-admin sandbox bypass via crafted HTML
High
CVE-2023-38286
was published
for
de.codecentric:spring-boot-admin-server
(Maven)
Jul 14, 2023
ELECOM wireless LAN routers WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and...
High
Unreviewed
CVE-2023-37566
was published
Jul 13, 2023
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and...
High
Unreviewed
CVE-2023-37568
was published
Jul 13, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36752
was published
Jul 11, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36754
was published
Jul 11, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36753
was published
Jul 11, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36751
was published
Jul 11, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36750
was published
Jul 11, 2023
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM...
High
Unreviewed
CVE-2023-36755
was published
Jul 11, 2023
An administrator is able to execute commands as root via the alerts management dialog
High
Unreviewed
CVE-2021-4406
was published
Jul 10, 2023
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor...
High
Unreviewed
CVE-2023-20889
was published
Jul 6, 2023
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS...
High
Unreviewed
CVE-2023-22788
was published
Jul 6, 2023
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS...
High
Unreviewed
CVE-2023-22789
was published
Jul 6, 2023
Multiple authenticated command injection vulnerabilities exist in the Aruba InstantOS and ArubaOS...
High
Unreviewed
CVE-2023-22790
was published
Jul 6, 2023
A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program...
High
Unreviewed
CVE-2023-22913
was published
Jul 6, 2023
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns...
High
Unreviewed
CVE-2023-22935
was published
Jul 6, 2023
An attacker with physical access to Moxa's bootloader versions of UC-8580 Series V1.1, UC-8540...
High
Unreviewed
CVE-2022-3086
was published
Jul 6, 2023
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1...
High
Unreviewed
CVE-2023-24520
was published
Jul 6, 2023
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality...
High
Unreviewed
CVE-2023-24583
was published
Jul 6, 2023
Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality...
High
Unreviewed
CVE-2023-24582
was published
Jul 6, 2023
Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1...
High
Unreviewed
CVE-2023-24519
was published
Jul 6, 2023
An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of...
High
Unreviewed
CVE-2023-23550
was published
Jul 6, 2023
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of...
High
Unreviewed
CVE-2023-22306
was published
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API