GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,992
Erlang
39
GitHub Actions
38
Go
2,634
Maven
5,000+
npm
4,258
NuGet
760
pip
4,051
Pub
12
RubyGems
955
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,577 advisories
Filter by severity
Excessive Attack Surface in pyload-ng
Critical
CVE-2023-0435
was published
for
pyload-ng
(pip)
Jan 23, 2023
Improper Input Validation in pyload-ng
Moderate
CVE-2023-0434
was published
for
pyload-ng
(pip)
Jan 22, 2023
Command Injection in Apache Airflow and Apache Airflow MySQL Provider
Critical
CVE-2023-22884
was published
for
apache-airflow
(pip)
Jan 21, 2023
Command injection in yiisoft/yii2-gii
High
CVE-2020-36655
was published
for
yiisoft/yii2-gii
(Composer)
Jan 21, 2023
git2-rs fails to verify SSH keys by default
Moderate
GHSA-m4ch-rfv5-x5g3
was published
for
git2
(Rust)
Jan 20, 2023
CakePHP vulnerable to Cross-site Scripting in some development error pages
Moderate
GHSA-xwhj-pqcg-8rcr
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP vulnerable to Remote File Inclusion through View template name manipulation
Moderate
GHSA-p76f-wr22-4rv6
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP allows direct access of prefixed controller actions
Moderate
GHSA-6hg4-vp5q-47mw
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP vulnerable to Denial of Service attack through XML payloads
High
GHSA-q79m-c546-2g63
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
CakePHP SecurityComponent cross form submission issue
Moderate
GHSA-j9q2-f9q7-jhgq
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
Shopware has Improper Input Validation issue in newsletter subscription
Moderate
CVE-2023-22734
was published
for
shopware/core
(Composer)
Jan 20, 2023
Shopware has Insufficient Session Expiration in Administration
Low
CVE-2023-22732
was published
for
shopware/core
(Composer)
Jan 20, 2023
CakePHP has incorrect Cross-Site Request Forgery validation
Moderate
GHSA-829q-v5g8-hhxc
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
ELF header parsing library doesn't check for valid offset
Moderate
GHSA-g6pw-999w-j75m
was published
for
elf_rs
(Rust)
Jan 20, 2023
scs-library-client may leak user credentials to third-party service via HTTP redirect
Moderate
CVE-2022-23538
was published
for
github.com/sylabs/scs-library-client
(Go)
Jan 20, 2023
bumpalo has use-after-free due to a lifetime error in `Vec::into_iter()`
Moderate
GHSA-f85w-wvc7-crwc
was published
for
bumpalo
(Rust)
Jan 20, 2023
ExifTool vulnerable to arbitrary code execution
High
GHSA-q95h-cqrv-8jv5
was published
for
exiftool_vendored
(RubyGems)
Jan 20, 2023
XpressEngine vulnerable to Unrestricted Upload of File with Dangerous Type
Critical
CVE-2021-26642
was published
for
xpressengine/xpressengine
(Composer)
Jan 20, 2023
Kraken has arbitrary file read vulnerability via component testfs
High
CVE-2022-47747
was published
for
github.com/uber/kraken
(Go)
Jan 20, 2023
Shopware's log module vulnerable to Improper Output Neutralization
Low
CVE-2023-22733
was published
for
shopware/core
(Composer)
Jan 20, 2023
CakePHP Database\\Query::offset() and limit() methods are vulnerable to SQL injection
Critical
CVE-2023-22727
was published
for
cakephp/cakephp
(Composer)
Jan 20, 2023
Deno is vulnerable to race condition via interactive permission prompt spoofing
High
CVE-2023-22499
was published
for
deno
(Rust)
Jan 20, 2023
pimcore is vulnerable to cross-site scripting via "title field " in data objects
Moderate
CVE-2023-0323
was published
for
pimcore/pimcore
(Composer)
Jan 20, 2023
act vulnerable to arbitrary file upload in artifact server
High
CVE-2023-22726
was published
for
github.com/nektos/act
(Go)
Jan 20, 2023
ProTip!
Advisories are also available from the
GraphQL API