GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
691 advisories
Filter by severity
Unrestricted file upload vulnerability in EMC Documentum WebTop 6.7SP1 before P31, 6.7SP2 before...
Moderate
Unreviewed
CVE-2015-4524
was published
May 17, 2022
IBM Rhapsody DM 4.0, 5.0 and 6.0 contains an undisclosed vulnerability that may allow an...
Moderate
Unreviewed
CVE-2016-8973
was published
May 17, 2022
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low...
Moderate
Unreviewed
CVE-2017-7989
was published
May 17, 2022
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to...
Moderate
Unreviewed
CVE-2015-4463
was published
May 17, 2022
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5...
Moderate
Unreviewed
CVE-2015-4462
was published
May 17, 2022
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user to upload...
Moderate
Unreviewed
CVE-2016-0354
was published
May 17, 2022
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in...
Moderate
Unreviewed
CVE-2017-14841
was published
May 17, 2022
A vulnerability in Cisco NX-OS System Software patch installation could allow an authenticated,...
Moderate
Unreviewed
CVE-2017-12332
was published
May 17, 2022
In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard...
Moderate
Unreviewed
CVE-2018-10521
was published
May 14, 2022
baserCMS arbitrary file upload vulnerability
Moderate
CVE-2018-0571
was published
for
baserproject/basercms
(Composer)
May 14, 2022
Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager...
Moderate
Unreviewed
CVE-2018-16373
was published
May 14, 2022
In LimeSurvey before 3.14.7, an admin user can leverage a "file upload" question to read an...
Moderate
Unreviewed
CVE-2018-16397
was published
May 14, 2022
SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=.....
Moderate
Unreviewed
CVE-2018-16821
was published
May 14, 2022
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative...
Moderate
Unreviewed
CVE-2018-19420
was published
May 14, 2022
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but Internet Explorer render HTML...
Moderate
Unreviewed
CVE-2018-19421
was published
May 14, 2022
An issue was discovered in Roche Accu-Chek Inform II Instrument before 03.06.00 (Serial number...
Moderate
Unreviewed
CVE-2018-18565
was published
May 14, 2022
In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system...
Moderate
Unreviewed
CVE-2018-16093
was published
May 14, 2022
LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5,...
Moderate
Unreviewed
CVE-2018-16097
was published
May 14, 2022
Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allows remote attackers to...
Moderate
Unreviewed
CVE-2019-8394
was published
May 14, 2022
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a...
Moderate
Unreviewed
CVE-2019-9692
was published
May 14, 2022
Symfony Path Disclosure
Moderate
CVE-2018-19789
was published
for
symfony/form
(Composer)
May 14, 2022
Drupal Settings Tray access bypass
Moderate
CVE-2017-6931
was published
for
drupal/core
(Composer)
May 13, 2022
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via...
Moderate
Unreviewed
CVE-2017-11404
was published
May 13, 2022
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via...
Moderate
Unreviewed
CVE-2017-11405
was published
May 13, 2022
On versions 11.2.1. and greater, unrestricted Snapshot File Access allows BIG-IP system's user...
Moderate
Unreviewed
CVE-2018-15333
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API