GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,603 advisories
Filter by severity
matrix-react-sdk Prototype pollution vulnerability
High
CVE-2022-36060
was published
for
matrix-react-sdk
(npm)
Mar 28, 2023
matrix-js-sdk Prototype Pollution vulnerability
High
CVE-2022-36059
was published
for
matrix-js-sdk
(npm)
Mar 28, 2023
Apache OpenMeetings missing authentication and can allow user impersonation
Critical
CVE-2023-28326
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
Mar 28, 2023
Comrak AST node data is not validated (GHSL-2023-049)
Moderate
CVE-2023-28631
was published
for
comrak
(Rust)
Mar 28, 2023
Comrak vulnerable to production of excessive output when parsing Markdown (GHSL-2023-048)
Moderate
GHSA-xxmq-4vph-956w
was published
for
comrak
(Rust)
Mar 28, 2023
Comrak vulnerable to quadratic runtime issues when parsing Markdown (GHSL-2023-047)
Moderate
CVE-2023-28626
was published
for
comrak
(Rust)
Mar 28, 2023
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
Critical
CVE-2023-20860
was published
for
org.springframework:spring
(Maven)
Mar 28, 2023
lambdaisland/uri `authority-regex` returns the wrong authority
Moderate
CVE-2023-28628
was published
for
lambdaisland:uri
(Maven)
Mar 27, 2023
Snappier vulnerable to buffer overrun due to improper restriction of operations within the bounds of a memory buffer
High
CVE-2023-28638
was published
for
Snappier
(NuGet)
Mar 27, 2023
Apiman vulnerable to permissions bypass due to missing check on API key URL
Moderate
CVE-2023-28640
was published
for
io.apiman:apiman-manager-api-rest-impl
(Maven)
Mar 27, 2023
Fluid Components TYPO3 extension vulnerable to Cross-Site Scripting
Moderate
CVE-2023-28604
was published
for
sitegeist/fluid-components
(Composer)
Mar 27, 2023
Podman Time-of-check Time-of-use (TOCTOU) Race Condition
Moderate
CVE-2023-0778
was published
for
github.com/containers/podman/v4
(Go)
Mar 27, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-22251
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows Improper Access Control
Moderate
CVE-2023-22250
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
pgAdmin 4 vulnerable to directory traversal
Moderate
CVE-2023-0241
was published
for
pgadmin4
(pip)
Mar 27, 2023
NATS TLS certificate common name validation bypass
Moderate
GHSA-wvc4-j7g5-4f79
was published
for
nats
(Rust)
Mar 27, 2023
TensorFlow Denial of Service vulnerability
Moderate
CVE-2023-25661
was published
for
tensorflow
(pip)
Mar 27, 2023
Complianz WordPress plugin vulnerable to cross-site scripting
Moderate
CVE-2023-1069
was published
for
really-simple-plugins/complianz-gdpr
(Composer)
Mar 27, 2023
Hippo4j allows attacker to obtain sensitive info via ConfigVerifyController function of Tenant Management module
Moderate
CVE-2023-27096
was published
for
cn.hippo4j:hippo4j-all
(Maven)
Mar 27, 2023
Apache InLong vulnerable to JDBC Deserialization of Untrusted Data
High
CVE-2023-27296
was published
for
org.apache.inlong:inlong-manager
(Maven)
Mar 27, 2023
Duplicate Advisory: pullit Command Injection vulnerability
High
GHSA-2w9p-xf5h-qwj3
was published
for
pullit
(npm)
Mar 27, 2023
•
withdrawn
GraphQL Java vulnerable to stack consumption
High
CVE-2023-28867
was published
for
com.graphql-java:graphql-java
(Maven)
Mar 27, 2023
redis-py Race Condition vulnerability
Moderate
CVE-2023-28858
was published
for
redis
(pip)
Mar 26, 2023
redis-py Race Condition due to incomplete fix
High
CVE-2023-28859
was published
for
redis
(pip)
Mar 26, 2023
ProTip!
Advisories are also available from the
GraphQL API