GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,557 advisories
Filter by severity
mlflow Command Injection vulnerability
High
CVE-2023-6940
was published
for
mlflow
(pip)
Dec 19, 2023
Corveda PHPSandbox Protection Mechanism Failure vulnerability
Moderate
CVE-2014-125107
was published
for
corveda/phpsandbox
(Composer)
Dec 19, 2023
Duplicate Advisory: Keycloak Open Redirect vulnerability
Moderate
GHSA-3p75-q5cc-qmj7
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 19, 2023
•
withdrawn
Grackle has StackOverflowError in GraphQL query processing
High
CVE-2023-50730
was published
for
edu.gemini:gsp-graphql-core_2.13
(Maven)
Dec 18, 2023
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Low
CVE-2023-50708
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Sentry's Astro SDK vulnerable to ReDoS
High
CVE-2023-50249
was published
for
@sentry/astro
(npm)
Dec 18, 2023
yiisoft/yii2-authclient's Oauth2 PKCE implementation is vulnerable
Moderate
CVE-2023-50714
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Resque vulnerable to Reflected Cross Site Scripting through pathnames
Moderate
CVE-2023-50724
was published
for
resque
(RubyGems)
Dec 18, 2023
Resque vulnerable to reflected XSS in resque-web failed and queues lists
Moderate
CVE-2023-50725
was published
for
resque
(RubyGems)
Dec 18, 2023
Resque vulnerable to reflected XSS in Queue Endpoint
Moderate
CVE-2023-50727
was published
for
resque
(RubyGems)
Dec 18, 2023
Maloja error page XSS vulnerability
Moderate
GHSA-4h72-34j6-j8x7
was published
for
malojaserver
(pip)
Dec 18, 2023
Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
Moderate
CVE-2023-6134
was published
for
org.keycloak:keycloak-services
(Maven)
Dec 18, 2023
Resque Scheduler Reflected XSS In Delayed Jobs View
Moderate
CVE-2022-44303
was published
for
resque-scheduler
(RubyGems)
Dec 18, 2023
Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin
Moderate
CVE-2023-48795
was published
for
golang.org/x/crypto
(Go)
Dec 18, 2023
AsyncSSH vulnerable to Prefix Truncation Attack (a.k.a. Terrapin Attack) against ChaCha20-Poly1305 and Encrypt-then-MAC
Moderate
GHSA-hfmc-7525-mj55
was published
for
asyncssh
(pip)
Dec 18, 2023
Zerocopy: Some Ref methods are unsound with some type parameters
Moderate
GHSA-rjhf-4mh8-9xjq
was published
for
zerocopy
(Rust)
Dec 18, 2023
Xnx3 Wangmarket Cross-Site Scripting vulnerability
Moderate
CVE-2023-6886
was published
for
com.xnx3.wangmarket:wangmarket
(Maven)
Dec 17, 2023
phpMyFAQ Cross-site Scripting vulnerability
Moderate
CVE-2023-6890
was published
for
thorsten/phpmyfaq
(Composer)
Dec 16, 2023
phpMyFAQ Cross-site Scripting vulnerability
Moderate
CVE-2023-6889
was published
for
thorsten/phpmyfaq
(Composer)
Dec 16, 2023
Unauthenticated Denial of Service in the octokit/webhooks library
High
CVE-2023-50728
was published
for
@octokit/app
(npm)
Dec 16, 2023
Remote code execution/programming rights with configuration section from any user account
Critical
CVE-2023-50723
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Dec 16, 2023
XSS/CSRF Remote Code Execution in XWiki.ConfigurableClass
Critical
CVE-2023-50722
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Dec 16, 2023
Remote code execution from account through SearchAdmin
Critical
CVE-2023-50721
was published
for
org.xwiki.platform:xwiki-platform-search-ui
(Maven)
Dec 16, 2023
Solr search discloses email addresses of users
Moderate
CVE-2023-50720
was published
for
org.xwiki.platform:xwiki-platform-search-solr-api
(Maven)
Dec 16, 2023
Solr search discloses password hashes of all users
High
CVE-2023-50719
was published
for
org.xwiki.platform:xwiki-platform-search-solr-api
(Maven)
Dec 16, 2023
ProTip!
Advisories are also available from the
GraphQL API