Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

24,577 advisories

Loading
Excessive Attack Surface in pyload-ng Critical
CVE-2023-0435 was published for pyload-ng (pip) Jan 23, 2023
Improper Input Validation in pyload-ng Moderate
CVE-2023-0434 was published for pyload-ng (pip) Jan 22, 2023
Command Injection in Apache Airflow and Apache Airflow MySQL Provider Critical
CVE-2023-22884 was published for apache-airflow (pip) Jan 21, 2023
Command injection in yiisoft/yii2-gii High
CVE-2020-36655 was published for yiisoft/yii2-gii (Composer) Jan 21, 2023
git2-rs fails to verify SSH keys by default Moderate
GHSA-m4ch-rfv5-x5g3 was published for git2 (Rust) Jan 20, 2023
CakePHP vulnerable to Cross-site Scripting in some development error pages Moderate
GHSA-xwhj-pqcg-8rcr was published for cakephp/cakephp (Composer) Jan 20, 2023
CakePHP vulnerable to Remote File Inclusion through View template name manipulation Moderate
GHSA-p76f-wr22-4rv6 was published for cakephp/cakephp (Composer) Jan 20, 2023
CakePHP allows direct access of prefixed controller actions Moderate
GHSA-6hg4-vp5q-47mw was published for cakephp/cakephp (Composer) Jan 20, 2023
CakePHP vulnerable to Denial of Service attack through XML payloads High
GHSA-q79m-c546-2g63 was published for cakephp/cakephp (Composer) Jan 20, 2023
CakePHP SecurityComponent cross form submission issue Moderate
GHSA-j9q2-f9q7-jhgq was published for cakephp/cakephp (Composer) Jan 20, 2023
Shopware has Improper Input Validation issue in newsletter subscription Moderate
CVE-2023-22734 was published for shopware/core (Composer) Jan 20, 2023
Shopware has Insufficient Session Expiration in Administration Low
CVE-2023-22732 was published for shopware/core (Composer) Jan 20, 2023
CakePHP has incorrect Cross-Site Request Forgery validation Moderate
GHSA-829q-v5g8-hhxc was published for cakephp/cakephp (Composer) Jan 20, 2023
ELF header parsing library doesn't check for valid offset Moderate
GHSA-g6pw-999w-j75m was published for elf_rs (Rust) Jan 20, 2023
scs-library-client may leak user credentials to third-party service via HTTP redirect Moderate
CVE-2022-23538 was published for github.com/sylabs/scs-library-client (Go) Jan 20, 2023
bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()` Moderate
GHSA-f85w-wvc7-crwc was published for bumpalo (Rust) Jan 20, 2023
Code injection in electerm Critical
CVE-2020-23256 was published for electerm (npm) Jan 20, 2023
ExifTool vulnerable to arbitrary code execution High
GHSA-q95h-cqrv-8jv5 was published for exiftool_vendored (RubyGems) Jan 20, 2023
dgollahon
Credited to dgollahon
XpressEngine vulnerable to Unrestricted Upload of File with Dangerous Type Critical
CVE-2021-26642 was published for xpressengine/xpressengine (Composer) Jan 20, 2023
Kraken has arbitrary file read vulnerability via component testfs High
CVE-2022-47747 was published for github.com/uber/kraken (Go) Jan 20, 2023
Shopware's log module vulnerable to Improper Output Neutralization Low
CVE-2023-22733 was published for shopware/core (Composer) Jan 20, 2023
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection Critical
CVE-2023-22727 was published for cakephp/cakephp (Composer) Jan 20, 2023
ravage84
Credited to ravage84
Deno is vulnerable to race condition via interactive permission prompt spoofing High
CVE-2023-22499 was published for deno (Rust) Jan 20, 2023
tristan-f-r another-rex
Credited to tristan-f-r and another-rex
pimcore is vulnerable to cross-site scripting via "title field " in data objects Moderate
CVE-2023-0323 was published for pimcore/pimcore (Composer) Jan 20, 2023
act vulnerable to arbitrary file upload in artifact server High
CVE-2023-22726 was published for github.com/nektos/act (Go) Jan 20, 2023
ProTip! Advisories are also available from the GraphQL API