GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,324
Erlang
31
GitHub Actions
21
Go
2,086
Maven
5,000+
npm
3,747
NuGet
674
pip
3,436
Pub
12
RubyGems
892
Rust
881
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
21,152 advisories
Filter by severity
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to SQL Injection via...
Critical
Unreviewed
CVE-2024-1981
was published
Feb 29, 2024
Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder allows Upload a Web...
Critical
Unreviewed
CVE-2025-23922
was published
Jan 16, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor allows...
Critical
Unreviewed
CVE-2025-23797
was published
Jan 16, 2025
An access control issue in the component formDMZ.cgi of D-Link 816A2_FWv1.10CNB05_R1B011D88210...
Critical
Unreviewed
CVE-2024-57684
was published
Jan 16, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57021
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57018
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57019
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57017
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57022
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57020
was published
Jan 15, 2025
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH...
Critical
Unreviewed
CVE-2025-22968
was published
Jan 15, 2025
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification...
Critical
Unreviewed
CVE-2024-57479
was published
Jan 15, 2025
Incorrect Access Control in Cfx.re FXServer v9601 and earlier allows unauthenticated users to...
Critical
Unreviewed
CVE-2024-46310
was published
Jan 13, 2025
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification...
Critical
Unreviewed
CVE-2024-57473
was published
Jan 15, 2025
Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
Critical
Unreviewed
CVE-2024-57483
was published
Jan 15, 2025
H3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification...
Critical
Unreviewed
CVE-2024-57480
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57015
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57016
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57012
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57011
was published
Jan 15, 2025
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection...
Critical
Unreviewed
CVE-2024-57013
was published
Jan 15, 2025
This issue was addressed through improved state management. This issue is fixed in iOS 17.5 and...
Critical
Unreviewed
CVE-2024-44136
was published
Jan 15, 2025
RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the...
Critical
Unreviewed
CVE-2025-22916
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the...
Critical
Unreviewed
CVE-2025-22913
was published
Jan 16, 2025
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter...
Critical
Unreviewed
CVE-2025-22905
was published
Jan 16, 2025
ProTip!
Advisories are also available from the
GraphQL API