GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,600 advisories
Filter by severity
Possible CSRF token fixation
Moderate
CVE-2023-25170
was published
for
prestashop/prestashop
(Composer)
Mar 13, 2023
Password Shucking Vulnerability
Moderate
CVE-2023-27580
was published
for
codeigniter4/shield
(Composer)
Mar 13, 2023
`out_reference::Out::from_raw` should be `unsafe`
Moderate
GHSA-p7mj-xvxg-grff
was published
for
out-reference
(Rust)
Mar 13, 2023
github-slug-action vulnerable to arbitrary code execution
High
CVE-2023-27581
was published
for
rlespinasse/github-slug-action
(GitHub Actions)
Mar 13, 2023
sqlite vulnerable to code execution due to Object coercion
High
CVE-2022-43441
was published
for
sqlite3
(npm)
Mar 13, 2023
Code Injection in alextselegidis/easyappointments
High
CVE-2023-1367
was published
for
alextselegidis/easyappointments
(Composer)
Mar 13, 2023
Cross-realm object access in Webpack 5
Critical
CVE-2023-28154
was published
for
webpack
(npm)
Mar 13, 2023
Cross Site Scripting in eZ Platform Ibexa Kernel
Moderate
CVE-2021-46875
was published
for
ezsystems/ezplatform-kernel
(Composer)
Mar 12, 2023
User account enumeration in eZ Publish Ibexa Kernel
Moderate
CVE-2021-46876
was published
for
ezsystems/ezpublish-kernel
(Composer)
Mar 12, 2023
Timing attack in eZ Platform Ibexa
Low
CVE-2022-48366
was published
for
ezsystems/ezplatform-kernel
(Composer)
Mar 12, 2023
Company admin role gives excessive privileges in eZ Platform Ibexa
High
CVE-2022-48365
was published
for
ezsystems/ezplatform-kernel
(Composer)
Mar 12, 2023
Access control issue in ezsystems/ezpublish-kernel
Critical
CVE-2022-48367
was published
for
ezsystems/ezpublish-kernel
(Composer)
Mar 12, 2023
Crossplane-runtime contains Improper Input Validation via Compositions
Moderate
CVE-2023-27484
was published
for
github.com/crossplane/crossplane
(Go)
Mar 10, 2023
HL7 FHIR Partial Path Zip Slip due to bypass of CVE-2023-24057
High
CVE-2023-28465
was published
for
ca.uhn.hapi.fhir:org.hl7.fhir.convertors
(Maven)
Mar 10, 2023
Denial of service in Jenkins Core
Moderate
CVE-2023-27900
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Information disclosure through error stack traces related to agents
Low
CVE-2023-27904
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Incorrect Authorization in Jenkins Core
Low
CVE-2023-27903
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Incorrect Permission Preservation in Jenkins Core
Moderate
CVE-2023-27902
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Denial of service in Jenkins Core
High
CVE-2023-27901
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Cross-site Scripting vulnerability in Jenkins
High
CVE-2023-27898
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Incorrect Authorization in Jenkins Core
High
CVE-2023-27899
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
Mar 10, 2023
Cross site scripting vulnerability in update-center2
Moderate
CVE-2023-27905
was published
for
org.jenkins-ci:update-center2
(Maven)
Mar 10, 2023
stoqey/gnuplot is vulnerable to command injection
Critical
CVE-2021-33360
was published
for
@stoqey/gnuplot
(npm)
Mar 10, 2023
Apache Log4j 1.x (EOL) allows Denial of Service (DoS)
High
CVE-2023-26464
was published
for
log4j:log4j
(Maven)
Mar 10, 2023
Funadmin vulnerable to SQL injection
Critical
CVE-2023-24774
was published
for
funadmin/funadmin
(Composer)
Mar 10, 2023
ProTip!
Advisories are also available from the
GraphQL API