GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,266
Erlang
31
GitHub Actions
21
Go
2,041
Maven
5,000+
npm
3,733
NuGet
662
pip
3,414
Pub
12
RubyGems
891
Rust
866
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
238,121 advisories
Filter by severity
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and...
Unknown
Unreviewed
CVE-2024-56174
was published
Dec 18, 2024
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and...
Unknown
Unreviewed
CVE-2024-56175
was published
Dec 18, 2024
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability ...
Moderate
Unreviewed
CVE-2024-12698
was published
Dec 18, 2024
The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12250
was published
Dec 18, 2024
The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all...
Moderate
Unreviewed
CVE-2024-12061
was published
Dec 18, 2024
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover...
High
Unreviewed
CVE-2024-12432
was published
Dec 18, 2024
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due...
High
Unreviewed
CVE-2024-21547
was published
Dec 18, 2024
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-12596
was published
Dec 18, 2024
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code...
High
Unreviewed
CVE-2024-21546
was published
Dec 18, 2024
The Cost Calculator Builder WordPress plugin before 3.2.43 does not have CSRF checks in some AJAX...
Unknown
Unreviewed
CVE-2024-10892
was published
Dec 18, 2024
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2024-12449
was published
Dec 18, 2024
Versions of the package bun before 1.1.30 are vulnerable to Prototype Pollution due to improper...
High
Unreviewed
CVE-2024-21548
was published
Dec 18, 2024
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation...
High
Unreviewed
CVE-2024-12259
was published
Dec 18, 2024
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests...
Unknown
Unreviewed
CVE-2024-56170
was published
Dec 18, 2024
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying...
Unknown
Unreviewed
CVE-2024-56169
was published
Dec 18, 2024
Authorization bypass through user-controlled key vulnerability in streaming service in Synology...
High
Unreviewed
CVE-2024-4464
was published
Dec 18, 2024
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and...
Unknown
Unreviewed
CVE-2024-56173
was published
Dec 18, 2024
The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy'...
High
Unreviewed
CVE-2024-12025
was published
Dec 18, 2024
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross...
Moderate
Unreviewed
CVE-2024-11254
was published
Dec 18, 2024
The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross...
Moderate
Unreviewed
CVE-2024-12500
was published
Dec 18, 2024
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution...
High
Unreviewed
CVE-2024-47480
was published
Dec 18, 2024
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
Moderate
Unreviewed
CVE-2024-11881
was published
Dec 18, 2024
The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin...
Moderate
Unreviewed
CVE-2024-11748
was published
Dec 18, 2024
The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2024-12513
was published
Dec 18, 2024
The ScanCircle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Moderate
Unreviewed
CVE-2024-11439
was published
Dec 18, 2024
ProTip!
Advisories are also available from the
GraphQL API