Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

24,600 advisories

Loading
SameSite Attribute vulnerability in pimCore High
CVE-2023-25240 was published for pimcore/pimcore (Composer) Feb 13, 2023
Cross-site Scripting in UDX Stateless Media Plugin Moderate
CVE-2022-4905 was published for wpcloud/wp-stateless (Composer) Feb 13, 2023
Path traversal vulnerability in glance Moderate
CVE-2022-25937 was published for glance (npm) Feb 13, 2023
lirantal
Credited to lirantal
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin Moderate
CVE-2023-25727 was published for phpmyadmin/phpmyadmin (Composer) Feb 13, 2023
MarkLee131
Credited to MarkLee131
Regular Expression Denial of Service in simple-markdown High
CVE-2019-25102 was published for simple-markdown (npm) Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq Moderate
CVE-2023-0786 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq Moderate
CVE-2023-0787 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Uncaught Exception in thorsten/phpmyfaq High
CVE-2023-0790 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Code Injection in thorsten/phpmyfaq Critical
CVE-2023-0788 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Command Injection in thorsten/phpmyfaq Critical
CVE-2023-0789 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Code Injection in thorsten/phpmyfaq Moderate
CVE-2023-0792 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq Moderate
CVE-2023-0791 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq Moderate
CVE-2023-0794 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Regular Expression Denial of Service in simple-markdown High
CVE-2019-25103 was published for simple-markdown (npm) Feb 12, 2023
Weak Password Requirements in thorsten/phpmyfaq High
CVE-2023-0793 was published for thorsten/phpmyfaq (Composer) Feb 12, 2023
Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit Moderate
CVE-2023-0780 was published for cockpit-hq/cockpit (Composer) Feb 11, 2023
Withdrawn: cacheable-request depends on http-cache-semantics, which is vulnerable to Regular Expression Denial of Service High
GHSA-8x6c-cv3v-vp6g was published for cacheable-request (npm) Feb 11, 2023 withdrawn
Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox High
GHSA-98hq-4wmw-98w9 was published for de.tum.in.ase:artemis-java-test-sandbox (Maven) Feb 10, 2023
LDAP
Credited to LDAP
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system Critical
CVE-2023-25168 was published for github.com/pterodactyl/wings (Go) Feb 10, 2023
T4x0r
Credited to T4x0r
Denial of service via HAMT Decoding Panics Moderate
CVE-2023-23625 was published for github.com/ipfs/go-unixfs (Go) Feb 10, 2023
Jorropo
Credited to Jorropo
Authentication Bypass in modoboa Critical
CVE-2023-0777 was published for modoboa (pip) Feb 10, 2023
IPython vulnerable to command injection via set_term_title Low
CVE-2023-24816 was published for ipython (pip) Feb 10, 2023
IPFS go-unixfsnode subject to DOS via HAMT Decoding Panics High
CVE-2023-23631 was published for github.com/ipfs/go-unixfsnode (Go) Feb 10, 2023
Jorropo
Credited to Jorropo
IPFS go-bitfield vulnerable to DoS via malformed size arguments Moderate
CVE-2023-23626 was published for github.com/ipfs/go-bitfield (Go) Feb 10, 2023
Jorropo
Credited to Jorropo
Formwork Cross-site Scripting (XSS) from Page title field Moderate
CVE-2023-24230 was published for getformwork/formwork (Composer) Feb 10, 2023
giuscris
Credited to giuscris
ProTip! Advisories are also available from the GraphQL API