GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,557 advisories
Filter by severity
Microsoft ASP.NET Core project templates vulnerable to denial of service
Moderate
CVE-2024-21319
was published
for
Microsoft.IdentityModel.JsonWebTokens
(NuGet)
Jan 9, 2024
react-native-mmkv Insertion of Sensitive Information into Log File vulnerability
Moderate
CVE-2024-21668
was published
for
react-native-mmkv
(npm)
Jan 9, 2024
Duplicate Advisory: NuGet Client Security Feature Bypass Vulnerability
Critical
GHSA-jw42-5m4v-9c8g
was published
for
NuGet.CommandLine
(NuGet)
Jan 9, 2024
•
withdrawn
Microsoft.Data.SqlClient and System.Data.SqlClient vulnerable to SQL Data Provider Security Feature Bypass
High
CVE-2024-0056
was published
for
Microsoft.Data.SqlClient
(NuGet)
Jan 9, 2024
Duplicate Advisory: Microsoft Identity Denial of service vulnerability
Moderate
GHSA-8g9c-28fc-mcx2
was published
for
Microsoft.IdentityModel.JsonWebTokens
(NuGet)
Jan 9, 2024
•
withdrawn
Microsoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerability
High
CVE-2024-21643
was published
for
Microsoft.IdentityModel.Protocols.SignedHttpRequest
(NuGet)
Jan 9, 2024
Parsing JSON serialized payload without protected field can lead to segfault
Moderate
CVE-2024-21664
was published
for
github.com/lestrrat-go/jwx
(Go)
Jan 9, 2024
fonttools XML External Entity Injection (XXE) Vulnerability
High
CVE-2023-45139
was published
for
fonttools
(pip)
Jan 9, 2024
Qualys Jenkins Plugin for WAS XML External Entity vulnerability
Moderate
CVE-2023-6149
was published
for
com.qualys.plugins:qualys-was
(Maven)
Jan 9, 2024
Apprite CLI makes Use of Hard-coded Credentials
Moderate
CVE-2023-50974
was published
for
appwrite
(npm)
Jan 9, 2024
Qualys Jenkins Plugin for Policy Compliance XML External Entity vulnerability
Moderate
CVE-2023-6147
was published
for
com.qualys.plugins:qualys-pc
(Maven)
Jan 9, 2024
Qualys Jenkins Plugin for Policy Compliance Cross-site Scripting vulnerability
Moderate
CVE-2023-6148
was published
for
com.qualys.plugins:qualys-pc
(Maven)
Jan 9, 2024
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
snapd Race Condition vulnerability
Critical
CVE-2022-3328
was published
for
github.com/snapcore/snapd
(Go)
Jan 8, 2024
CIRCL's Kyber: timing side-channel (kyberslash2)
High
GHSA-9763-4f94-gfch
was published
for
github.com/cloudflare/circl
(Go)
Jan 8, 2024
XWiki vulnerable to Denial of Service attack through attachments
High
CVE-2024-21651
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Jan 8, 2024
XWiki Remote Code Execution Vulnerability via User Registration
Critical
CVE-2024-21650
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Jan 8, 2024
XWiki has no right protection on rollback action
High
CVE-2024-21648
was published
for
org.xwiki.platform:xwiki-platform
(Maven)
Jan 8, 2024
Puma HTTP Request/Response Smuggling vulnerability
Moderate
CVE-2024-21647
was published
for
puma
(RubyGems)
Jan 8, 2024
pyload Unauthenticated Flask Configuration Leakage vulnerability
High
CVE-2024-21644
was published
for
pyload-ng
(pip)
Jan 8, 2024
pyload Log Injection vulnerability
Moderate
CVE-2024-21645
was published
for
pyload-ng
(pip)
Jan 8, 2024
@fastify/reply-from JSON Content-Type parsing confusion
Moderate
CVE-2023-51701
was published
for
@fastify/reply-from
(npm)
Jan 8, 2024
Apache Axis Improper Input Validation vulnerability
High
CVE-2023-51441
was published
for
axis:axis
(Maven)
Jan 6, 2024
D-Tale server-side request forgery through Web uploads
High
CVE-2024-21642
was published
for
dtale
(pip)
Jan 5, 2024
Flarum's logout Route allows open redirects
Moderate
CVE-2024-21641
was published
for
flarum/core
(Composer)
Jan 5, 2024
ProTip!
Advisories are also available from the
GraphQL API