GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
48 advisories
Filter by severity
The WordPress Post Grid Layouts with Pagination – Sogrid plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-8392
was published
Oct 26, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49701
was published
Oct 23, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49690
was published
Oct 23, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49243
was published
Oct 18, 2024
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49317
was published
Oct 17, 2024
: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-49251
was published
Oct 16, 2024
: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2024-48029
was published
Oct 16, 2024
The ee-class from FormosaSoft does not properly validate a specific page parameter, allowing...
High
Unreviewed
CVE-2024-9981
was published
Oct 15, 2024
The Clean Login plugin for WordPress is vulnerable to Local File Inclusion in all versions up to,...
High
Unreviewed
CVE-2024-8252
was published
Aug 30, 2024
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This...
High
Unreviewed
CVE-2024-5762
was published
Aug 21, 2024
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Local File Inclusion...
High
Unreviewed
CVE-2024-6589
was published
Jul 25, 2024
This High severity File Inclusion vulnerability was introduced in versions 9.0.0, 9.1.0, 9.2.0, 9...
High
Unreviewed
CVE-2024-21687
was published
Jul 16, 2024
Sourcecodester Gas Agency Management System v1.0 is vulnerable to arbitrary code execution via...
High
Unreviewed
CVE-2024-36569
was published
Jun 3, 2024
A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a...
High
Unreviewed
CVE-2023-52325
was published
Jan 23, 2024
The HTML filter and csv-file search plugin for WordPress is vulnerable to Local File Inclusion in...
High
Unreviewed
CVE-2023-5099
was published
Oct 31, 2023
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution...
High
Unreviewed
CVE-2023-5199
was published
Oct 30, 2023
The Grid Plus plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and...
High
Unreviewed
CVE-2023-5250
was published
Oct 30, 2023
FUXA local file inclusion vulnerability
High
CVE-2023-31718
was published
for
fuxa-server
(npm)
Sep 22, 2023
FUXA vulnerable to Local File Inclusion
High
CVE-2023-31716
was published
for
@frangoteam/fuxa
(npm)
Sep 22, 2023
Flarum vulnerable to LFI and Blind SSRF via Avatar upload
High
CVE-2023-40033
was published
for
flarum/core
(Composer)
Aug 16, 2023
The wpForo Forum plugin for WordPress is vulnerable to Local File Include, Server-Side Request...
High
Unreviewed
CVE-2023-2249
was published
Jun 9, 2023
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.
High
Unreviewed
CVE-2023-2551
was published
May 5, 2023
Improper file handling in concrete5/core
High
CVE-2021-22968
was published
for
concrete5/core
(Composer)
Nov 23, 2021
ProTip!
Advisories are also available from the
GraphQL API