GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,092 advisories
Filter by severity
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
High
Unreviewed
CVE-2024-42991
was published
Sep 3, 2024
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401. Due to improper user...
High
Unreviewed
CVE-2024-45171
was published
Sep 5, 2024
The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin...
High
Unreviewed
CVE-2024-7770
was published
Sep 10, 2024
An arbitrary file upload vulnerability in the component /admin/index.php of moziloCMS v3.0 allows...
High
Unreviewed
CVE-2024-44871
was published
Sep 10, 2024
SpiderControl SCADA Web Server has a vulnerability that could allow an
attacker to upload...
High
Unreviewed
CVE-2024-8232
was published
Sep 10, 2024
Contao affected by remote command execution through file upload
High
CVE-2024-45398
was published
for
contao/core-bundle
(Composer)
Sep 17, 2024
Dedecms V5.7.115 contains an arbitrary code execution via file upload vulnerability in the backend.
High
Unreviewed
CVE-2024-46373
was published
Sep 18, 2024
An arbitrary file upload vulnerability in the Media Manager function of Closed-Loop Technology...
High
Unreviewed
CVE-2024-40125
was published
Sep 19, 2024
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary...
High
Unreviewed
CVE-2023-26690
was published
Sep 25, 2024
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the ...
High
Unreviewed
CVE-2024-8126
was published
Sep 26, 2024
An arbitrary file upload vulnerability in YPay 1.2.0 allows attackers to execute arbitrary code...
High
Unreviewed
CVE-2024-46441
was published
Sep 27, 2024
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
High
Unreviewed
CVE-2024-7855
was published
Oct 2, 2024
This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files...
High
Unreviewed
CVE-2024-47655
was published
Oct 4, 2024
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote...
High
Unreviewed
CVE-2024-37868
was published
Oct 4, 2024
File Upload vulnerability in Itsourcecode Online Discussion Forum Project v.1.0 allows a remote...
High
Unreviewed
CVE-2024-37869
was published
Oct 4, 2024
Unrestricted Upload of File with Dangerous Type vulnerability in Bit Apps Bit Form – Contact Form...
High
Unreviewed
CVE-2024-47319
was published
Oct 5, 2024
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a...
High
Unreviewed
CVE-2024-37179
was published
Oct 8, 2024
Livewire Remote Code Execution on File Uploads
High
CVE-2024-47823
was published
for
livewire/livewire
(Composer)
Oct 8, 2024
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of...
High
Unreviewed
CVE-2024-47423
was published
Oct 9, 2024
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with...
High
Unreviewed
CVE-2024-45136
was published
Oct 9, 2024
InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File...
High
Unreviewed
CVE-2024-45137
was published
Oct 9, 2024
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing...
High
Unreviewed
CVE-2024-9981
was published
Oct 15, 2024
The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and...
High
Unreviewed
CVE-2024-8746
was published
Oct 16, 2024
The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all...
High
Unreviewed
CVE-2024-8918
was published
Oct 16, 2024
The Migration, Backup, Staging – WPvivid plugin for WordPress is vulnerable to arbitrary file...
High
Unreviewed
CVE-2020-36842
was published
Oct 16, 2024
ProTip!
Advisories are also available from the
GraphQL API