Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

24,600 advisories

Loading
XWiki Platform subject to Uncontrolled Resource Consumption Moderate
CVE-2023-26470 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Mar 3, 2023
XWiki Platform users may execute anything with superadmin right through comments and async macro Critical
CVE-2023-26471 was published for org.xwiki.platform:xwiki-platform-rendering-async-macro (Maven) Mar 3, 2023
XWiki Platform may allow privilege escalation to programming rights via user's first name Critical
CVE-2023-26055 was published for org.xwiki.commons:xwiki-commons-xml (Maven) Mar 3, 2023
XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile Critical
CVE-2023-26472 was published for org.xwiki.platform:xwiki-platform-icon-ui (Maven) Mar 3, 2023
XWiki Platform vulnerable to privilege escalation via properties with wiki syntax that are executed with wrong author Critical
CVE-2023-26474 was published for org.xwiki.platform:xwiki-platform-legacy-oldcore (Maven) Mar 3, 2023
XWiki Platform packages Expose Sensitive Information to an Unauthorized Actor High
CVE-2023-26476 was published for org.xwiki.platform:xwiki-platform-livetable-ui (Maven) Mar 3, 2023
Unprivileged XWiki Platform users can make arbitrary select queries using DatabaseListProperty and suggest.vm Moderate
CVE-2023-26473 was published for org.xwiki.platform:xwiki-platform-web (Maven) Mar 3, 2023
Craft CMS Stored Cross-site Scripting Injection Vulnerability Moderate
CVE-2023-23927 was published for craftcms/cms (Composer) Mar 3, 2023
gabriel-vernilo brandonkelly
Credited to gabriel-vernilo and brandonkelly
Opencontainers runc Incorrect Authorization vulnerability High
CVE-2023-27561 was published for github.com/opencontainers/runc (Go) Mar 3, 2023
AkihiroSuda
Credited to AkihiroSuda
OpenZeppelin Contracts contains Incorrect Calculation Moderate
CVE-2023-26488 was published for @openzeppelin/contracts (npm) Mar 3, 2023
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints Moderate
CVE-2022-2837 was published for github.com/coredns/coredns (Go) Mar 3, 2023
chrisbloom7
Credited to chrisbloom7
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints Moderate
CVE-2022-2835 was published for github.com/coredns/coredns (Go) Mar 3, 2023
phpseclib Infinite Loop vulnerability High
CVE-2023-27560 was published for phpseclib/phpseclib (Composer) Mar 3, 2023
janedbal
Credited to janedbal
Cockpit Uses Platform-Dependent Third Party Components Moderate
CVE-2023-1160 was published for cockpit-hq/cockpit (Composer) Mar 3, 2023
Vega vulnerable to arbitrary code execution when clicking href links Moderate
GHSA-cp47-r258-q626 was published for vega (npm) Mar 2, 2023
Keycloak vulnerable to user impersonation via stolen UUID code High
CVE-2023-0264 was published for org.keycloak:keycloak-services (Maven) Mar 2, 2023
JorXi
Credited to JorXi
keycloak-connect contains Open redirect vulnerability in the Node.js adapter Moderate
CVE-2022-2237 was published for keycloak-connect (npm) Mar 2, 2023
jviding
Credited to jviding
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb Moderate
CVE-2023-26483 was published for github.com/russellhaering/gosaml2 (Go) Mar 2, 2023
nszetei
Credited to nszetei
Vega Expression Language `scale` expression function Cross Site Scripting Moderate
CVE-2023-26486 was published for vega (npm) Mar 2, 2023
ajxchapman hydrosquall
Credited to ajxchapman and hydrosquall
Vega has Cross-site Scripting vulnerability in `lassoAppend` function Moderate
CVE-2023-26487 was published for vega (npm) Mar 2, 2023
azasypkin jkakavas
Credited to azasypkin and jkakavas
Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions Low
CVE-2023-26052 was published for saleor (pip) Mar 2, 2023
xwiki-platform vulnerable to Remote Code Execution in Annotations Critical
CVE-2023-26475 was published for org.xwiki.platform:xwiki-platform-annotation-ui (Maven) Mar 2, 2023
renniepak
Credited to renniepak
Pimcore vulnerable to Cross Site Scripting in Email Blacklist Moderate
CVE-2023-1116 was published for pimcore/pimcore (Composer) Mar 1, 2023
0xy37 ahmedvienna
Credited to 0xy37 and ahmedvienna
Pimcore vulnerable to Cross Site Scripting in image/video thumbnail config Moderate
CVE-2023-1117 was published for pimcore/pimcore (Composer) Mar 1, 2023
ProTip! Advisories are also available from the GraphQL API