GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,264
NuGet
760
pip
4,060
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,614 advisories
Filter by severity
Mattermost vulnerable to information disclosure
Moderate
CVE-2023-1777
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 31, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability
Moderate
CVE-2023-1760
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
phpMyFAQ Cross-site Scripting vulnerability
Moderate
CVE-2023-1755
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
phpMyFAQ has weak password requirements
Moderate
CVE-2023-1753
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
phpMyFAQ Stored Cross-site Scripting vulnerability
Moderate
CVE-2023-1759
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
phpMyFAQ vulnerable to improper input validation
Moderate
CVE-2023-1754
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
phpMyFAQ Code Injection vulnerability
Moderate
CVE-2023-1761
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
thorsten/phpmyfaq vulnerable privilege escalation from improper privilege management
High
CVE-2023-1762
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
jeecg-boot vulnerable to SQL injection
Critical
CVE-2023-1741
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
Mar 31, 2023
unpoly-rails Denial of Service vulnerability
Moderate
CVE-2023-28846
was published
for
unpoly-rails
(RubyGems)
Mar 30, 2023
mindsdb arbitrary file write when extracting a remotely retrieved Tarball
High
CVE-2023-30620
was published
for
mindsdb
(pip)
Mar 30, 2023
Payara Server allows remote attackers to load malicious code on the server once a JNDI directory scan is performed
Critical
CVE-2023-28462
was published
for
fish.payara.server:payara-aggregator
(Maven)
Mar 30, 2023
runc AppArmor bypass with symlinked /proc
Moderate
CVE-2023-28642
was published
for
github.com/opencontainers/runc
(Go)
Mar 30, 2023
Prototype pollution in matrix-js-sdk (part 2)
High
CVE-2023-28427
was published
for
matrix-js-sdk
(npm)
Mar 30, 2023
Kiwi TCMS Stored Cross-site Scripting via SVG file
High
CVE-2023-27489
was published
for
kiwitcms
(pip)
Mar 30, 2023
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
Low
CVE-2023-25809
was published
for
github.com/opencontainers/runc
(Go)
Mar 30, 2023
Arbitrary file write in mindsdb when Extracting Tarballs retrieved from a remote location
Moderate
CVE-2022-23522
was published
for
mindsdb
(pip)
Mar 30, 2023
Apache UIMA DUCC allows remote code execution
High
CVE-2023-28935
was published
for
org.apache.uima:uima-ducc-parent
(Maven)
Mar 30, 2023
Use of hard-coded, security-relevant constants in deepset-ai/haystack
Critical
CVE-2023-1712
was published
for
farm-haystack
(pip)
Mar 30, 2023
angular vulnerable to regular expression denial of service via the angular.copy() utility
Moderate
CVE-2023-26116
was published
for
angular
(npm)
Mar 30, 2023
angular vulnerable to regular expression denial of service via the $resource service
Moderate
CVE-2023-26117
was published
for
angular
(npm)
Mar 30, 2023
angular vulnerable to regular expression denial of service via the <input type="url"> element
Moderate
CVE-2023-26118
was published
for
angular
(npm)
Mar 30, 2023
HashiCorp Vault's PKI mount vulnerable to denial of service
Moderate
CVE-2023-0665
was published
for
github.com/hashicorp/vault
(Go)
Mar 30, 2023
ProTip!
Advisories are also available from the
GraphQL API