GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,603 advisories
Filter by severity
baserCMS File Uploader Remote Code Execution (RCE) vulnerability
Critical
CVE-2023-25654
was published
for
baserproject/basercms
(Composer)
Mar 23, 2023
Non-interactive Tailscale SSH sessions on FreeBSD may use the effective group ID of the tailscaled process
Moderate
CVE-2023-28436
was published
for
tailscale.com
(Go)
Mar 23, 2023
Argo CD authenticated but unauthorized users may enumerate Application names via the API
Moderate
CVE-2022-41354
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 23, 2023
directus vulnerable to Insertion of Sensitive Information into Log File
Moderate
CVE-2023-28443
was published
for
directus
(npm)
Mar 23, 2023
Hippo4j privilege escalation issue
High
CVE-2023-27094
was published
for
cn.hippo4j:hippo4j-all
(Maven)
Mar 23, 2023
Duplicate Advisory: Grafana Stored Cross-site Scripting vulnerability
Moderate
GHSA-3cgw-hfw7-wc7j
was published
for
github.com/grafana/grafana
(Go)
Mar 23, 2023
•
withdrawn
code-server vulnerable to Missing Origin Validation in WebSockets
Critical
CVE-2023-26114
was published
for
code-server
(npm)
Mar 23, 2023
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
Moderate
GHSA-255r-3prx-mf99
was published
for
rmp-serde
(Rust)
Mar 22, 2023
OpenNMS Meridian and Horizon vulnerable to Cross-Site Request Forgery
Moderate
CVE-2023-0870
was published
for
org.opennms:opennms-webapp
(Maven)
Mar 22, 2023
Gophish vulnerable to Cross-site Scripting via crafted landing page
Moderate
CVE-2022-45004
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
Gophish vulnerable to Denial of Service via crafted payload involving autofocus
High
CVE-2022-45003
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
High
CVE-2023-28119
was published
for
github.com/crewjam/saml
(Go)
Mar 22, 2023
Pimcore vulnerable to improper quoting of filters in Custom Reports
Moderate
CVE-2023-28438
was published
for
pimcore/pimcore
(Composer)
Mar 22, 2023
Pimcore Remote Code Execution vulnerability in Search function
Moderate
CVE-2023-1578
was published
for
pimcore/pimcore
(Composer)
Mar 22, 2023
Apache Tomcat vulnerable to Unprotected Transport of Credentials
Moderate
CVE-2023-28708
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Mar 22, 2023
Jettison vulnerable to infinite recursion
High
CVE-2023-1436
was published
for
org.codehaus.jettison:jettison
(Maven)
Mar 22, 2023
dio vulnerable to CRLF injection with HTTP method string
High
CVE-2021-31402
was published
for
dio
(Pub)
Mar 21, 2023
cloudflared's Installer has Local Privilege Escalation Vulnerability
High
CVE-2023-1314
was published
for
github.com/cloudflare/cloudflared
(Go)
Mar 21, 2023
Frontier's modexp precompile is slow for even modulus
High
CVE-2023-28431
was published
for
pallet-evm-precompile-modexp
(Rust)
Mar 21, 2023
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
High
CVE-2023-28117
was published
for
sentry-sdk
(pip)
Mar 21, 2023
`cilium-cli` disables etcd authorization for clustermesh clusters
Moderate
CVE-2023-28114
was published
for
github.com/cilium/cilium-cli
(Go)
Mar 21, 2023
Xuxueli xxl-job allows attacker to obtain sensitive information via the pageList parameter
High
CVE-2023-27087
was published
for
com.xuxueli:xxl-job
(Maven)
Mar 21, 2023
weixin-python XML External Entity vulnerability
Critical
CVE-2018-25082
was published
for
weixin-python
(pip)
Mar 21, 2023
Teampass SQL Injection vulnerability
High
CVE-2023-1545
was published
for
nilsteampassnet/teampass
(Composer)
Mar 21, 2023
Answer vulnerable to Business Logic Errors
Low
CVE-2023-1541
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
ProTip!
Advisories are also available from the
GraphQL API