GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,096
Erlang
29
GitHub Actions
19
Go
1,925
Maven
5,000+
npm
3,654
NuGet
638
pip
3,263
Pub
10
RubyGems
873
Rust
823
Swift
35
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly...
Critical
Unreviewed
CVE-2024-41925
was published
Oct 4, 2024
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2024-8252
was published
Aug 30, 2024
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5762
was published
Aug 21, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-43261
was published
Aug 19, 2024
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel,...
Moderate
Unreviewed
CVE-2024-4359
was published
Aug 12, 2024
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion...
High
Unreviewed
CVE-2024-6589
was published
Jul 25, 2024
This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9...
High
Unreviewed
CVE-2024-21687
was published
Jul 16, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Moderate
Unreviewed
CVE-2024-35650
was published
Jun 10, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
Critical
Unreviewed
CVE-2024-35629
was published
Jun 4, 2024
Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via...
High
Unreviewed
CVE-2024-36569
was published
Jun 3, 2024
An issue was discovered in linqi before 1.4.0.1 on Windows. There is /api/Cdn/GetFile local file...
Critical
Unreviewed
CVE-2024-33863
was published
May 14, 2024
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application,...
Critical
Unreviewed
CVE-2024-1600
was published
Apr 10, 2024
Arbitrary file upload vulnerability in Sourcecodester Complete E-Commerce Site v1.0, allows...
Critical
Unreviewed
CVE-2024-30849
was published
Apr 5, 2024
A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a...
High
Unreviewed
CVE-2023-52325
was published
Jan 23, 2024
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704....
Moderate
Unreviewed
CVE-2024-0315
was published
Jan 15, 2024
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in...
High
Unreviewed
CVE-2023-5099
was published
Oct 31, 2023
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution...
High
Unreviewed
CVE-2023-5199
was published
Oct 30, 2023
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and...
High
Unreviewed
CVE-2023-5250
was published
Oct 30, 2023
The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to,...
Critical
Unreviewed
CVE-2023-4488
was published
Oct 20, 2023
FUXA local file inclusion vulnerability
High
CVE-2023-31718
was published
for
fuxa-server
(npm)
Sep 22, 2023
FUXA vulnerable to Local File Inclusion
High
CVE-2023-31716
was published
for
@frangoteam/fuxa
(npm)
Sep 22, 2023
Yii2 allows attackers to execute any local .php file via a relative path in the view parameter
Critical
CVE-2015-5467
was published
for
yiisoft/yii2
(Composer)
Sep 21, 2023
An issue was discovered in Geomatika IsiGeo Web 6.0. It allows remote authenticated users to...
Moderate
Unreviewed
CVE-2023-23565
was published
Aug 22, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
High
CVE-2023-40033
was published
for
flarum/core
(Composer)
Aug 16, 2023
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in versions up to, and...
Critical
Unreviewed
CVE-2023-3452
was published
Aug 12, 2023
ProTip!
Advisories are also available from the
GraphQL API