Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

24,603 advisories

Loading
Cross-site Scripting (XSS) in UrlSlug Data type Moderate
CVE-2023-28106 was published for pimcore/pimcore (Composer) Mar 17, 2023
Authorization Bypass Through User-Controlled Key play-with-docker Moderate
CVE-2023-28109 was published for github.com/play-with-docker/play-with-docker (Go) Mar 17, 2023
cokeBeer
Credited to cokeBeer
Streamlit publishes previously-patched Cross-site Scripting vulnerability Moderate
CVE-2023-27494 was published for streamlit (pip) Mar 17, 2023
russh may use insecure Diffie-Hellman keys Moderate
CVE-2023-28113 was published for russh (Rust) Mar 17, 2023
Holzhaus lambdafu
Credited to Holzhaus and lambdafu
Improper Authorization in nilsteampassnet/teampass Moderate
CVE-2023-1463 was published for nilsteampassnet/teampass (Composer) Mar 17, 2023
jeecg-boot SQL Injection vulnerability Critical
CVE-2023-1454 was published for org.jeecgframework.boot:jeecg-boot-common (Maven) Mar 17, 2023
Reflective Cross-site Scripting Vulnerability in twitter-bootstrap-rails Moderate
CVE-2014-4920 was published for twitter-bootstrap-rails (RubyGems) Mar 16, 2023
Reflected XSS in Application Logger module Moderate
GHSA-2xpm-cmvw-3jcc was published for pimcore/pimcore (Composer) Mar 16, 2023
khanhchauminh
Credited to khanhchauminh
Cross-site Scripting (XSS) in Document Types Moderate
CVE-2023-1429 was published for pimcore/pimcore (Composer) Mar 16, 2023
khanhchauminh
Credited to khanhchauminh
Cross-site Scripting (XSS) - stored in Print Documents Moderate
GHSA-rrwm-8wqm-gwgv was published for pimcore/pimcore (Composer) Mar 16, 2023
vishnuraj-r
Credited to vishnuraj-r
Go-huge-util vulnerable to path traversal when unzipping files High
CVE-2023-28105 was published for github.com/dablelv/go-huge-util (Go) Mar 16, 2023
cokeBeer
Credited to cokeBeer
DDOS attack on graphql endpoints High
CVE-2023-28104 was published for silverstripe/graphql (Composer) Mar 16, 2023
GuySartorelli
Credited to GuySartorelli
Authelia allows open redirects on the logout endpoint Moderate
CVE-2021-29456 was published for github.com/authelia/authelia/v4 (Go) Mar 16, 2023
jonbayl
Credited to jonbayl
On a compromised node, the virt-handler service account can be used to modify all node specs High
CVE-2023-26484 was published for kubevirt.io/kubevirt (Go) Mar 16, 2023
younaman XDTG
Credited to younaman and XDTG
Server-Side Request Forgery in Request Moderate
CVE-2023-28155 was published for @cypress/request (npm) Mar 16, 2023
NikoRaisanen G-Rath
Credited to NikoRaisanen and G-Rath
Exposure of Sensitive Information in OpenGoofy Hippo4j Moderate
CVE-2023-27095 was published for cn.hippo4j:hippo4j-core (Maven) Mar 16, 2023
Possible Denial of Service Vulnerability in Rack's header parsing Low
CVE-2023-27539 was published for rack (RubyGems) Mar 15, 2023
G-Rath
Credited to G-Rath
Possible XSS Security Vulnerability in SafeBuffer#bytesplice Moderate
CVE-2023-28120 was published for activesupport (RubyGems) Mar 15, 2023
Arbitrary local file read vulnerability during template rendering High
CVE-2023-25345 was published for swig (npm) Mar 15, 2023
Improper Input Validation In Eclipse BIRT High
CVE-2023-0100 was published for org.eclipse.birt:org.eclipse.birt.report.viewer (Maven) Mar 15, 2023
Sensitive Information in Error Messages in Apache Airflow Moderate
CVE-2023-25695 was published for apache-airflow (pip) Mar 15, 2023
google.golang.org/protobuf vulnerable to panic leading to denial of service High
CVE-2023-24535 was published for google.golang.org/protobuf (Go) Mar 14, 2023
Full authentication bypass if SASL authorization username is specified Critical
CVE-2023-27582 was published for github.com/foxcpp/maddy (Go) Mar 14, 2023
Nomad Job Submitter Privilege Escalation Using Workload Identity High
CVE-2023-1299 was published for github.com/hashicorp/nomad (Go) Mar 14, 2023
ONOS vulnerable to reflected cross-site scripting Moderate
CVE-2023-24279 was published for org.onosproject:onos-archetypes (Maven) Mar 14, 2023
edoardottt
Credited to edoardottt
ProTip! Advisories are also available from the GraphQL API