GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,600 advisories
Filter by severity
iziModal Cross-site Scripting vulnerability
Moderate
CVE-2021-32860
was published
for
izimodal
(npm)
Feb 21, 2023
Baremetrics date range picker vulnerable to Cross-site Scripting
Moderate
CVE-2021-32859
was published
for
baremetrics-calendar
(npm)
Feb 21, 2023
textAngular Cross-site Scripting vulnerability
Moderate
CVE-2021-32854
was published
for
textangular
(npm)
Feb 21, 2023
Erxes vulnerable to Cross-site Scripting
Moderate
CVE-2021-32853
was published
for
erxes
(npm)
Feb 21, 2023
Mind-elixir Cross-site Scripting vulnerability
Moderate
CVE-2021-32851
was published
for
mind-elixir
(npm)
Feb 21, 2023
@claviska/jquery-minicolors vulnerable to Cross-site Scripting
Moderate
CVE-2021-32850
was published
for
@claviska/jquery-minicolors
(npm)
Feb 21, 2023
Apache Kerby LdapIdentityBackend LDAP Injection vulnerability
Critical
CVE-2023-25613
was published
for
org.apache.kerby:ldap-backend
(Maven)
Feb 20, 2023
Apache Commons FileUpload denial of service vulnerability
High
CVE-2023-24998
was published
for
commons-fileupload:commons-fileupload
(Maven)
Feb 20, 2023
generator-hottowel Cross-site Scripting vulnerability
Moderate
CVE-2016-15025
was published
for
generator-hottowel
(npm)
Feb 20, 2023
dd-plist XML External Entitly vulnerability
High
CVE-2016-15026
was published
for
com.googlecode.plist:dd-plist
(Maven)
Feb 20, 2023
java-xmlbuilder vulnerable to XML External Entity Reference
Critical
CVE-2014-125087
was published
for
com.jamesmurty.utils:java-xmlbuilder
(Maven)
Feb 19, 2023
Pixelfed may allow unauthorized actor to view private posts
Moderate
CVE-2023-0914
was published
for
pixelfed/pixelfed
(Composer)
Feb 19, 2023
Pixelfed allows user enumeration via reset password functionality
Moderate
CVE-2023-0901
was published
for
pixelfed/pixelfed
(Composer)
Feb 18, 2023
Stored cross site scripting in changedetection.io
Moderate
CVE-2023-24769
was published
for
changedetection.io
(pip)
Feb 18, 2023
Duplicate Advisory: Insecure Temporary File in RESTEasy
Moderate
GHSA-jrmh-v64j-mjm9
was published
for
org.jboss.resteasy:resteasy-core
(Maven)
Feb 18, 2023
•
withdrawn
Cross-site Scripting in jspreadsheet
Moderate
CVE-2022-48115
was published
for
jspreadsheet-ce
(npm)
Feb 18, 2023
Moodle Improper Access Control vulnerability
High
CVE-2023-23923
was published
for
moodle/moodle
(Composer)
Feb 17, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2023-23921
was published
for
moodle/moodle
(Composer)
Feb 17, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2023-23922
was published
for
moodle/moodle
(Composer)
Feb 17, 2023
User data in TPM attestation vulnerable to MITM
High
GHSA-r2h5-3hgw-8j34
was published
for
github.com/edgelesssys/constellation/v2
(Go)
Feb 17, 2023
Privilege escalation in MOSN
Critical
CVE-2021-32163
was published
for
mosn.io/mosn
(Go)
Feb 17, 2023
Server-Side Request Forgery in Plone CMS
High
CVE-2021-33926
was published
for
Plone
(pip)
Feb 17, 2023
golang.org/x/net vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-41723
was published
for
golang.org/x/net
(Go)
Feb 17, 2023
Uncontrolled Resource Consumption in golang.org/x/image
Moderate
CVE-2022-41727
was published
for
golang.org/x/image
(Go)
Feb 17, 2023
Misinterpretation of Input in thorsten/phpmyfaq
Moderate
CVE-2023-0880
was published
for
thorsten/phpmyfaq
(Composer)
Feb 17, 2023
ProTip!
Advisories are also available from the
GraphQL API