GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
27,762 advisories
Filter by severity
xwiki-platform-web-templates vulnerable to Eval Injection
Critical
CVE-2023-29512
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 20, 2023
Spring Boot Security Bypass with Wildcard Pattern Matching on Cloud Foundry
Critical
CVE-2023-20873
was published
for
org.springframework.boot:spring-boot-actuator-autoconfigure
(Maven)
Apr 20, 2023
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated,...
Critical
Unreviewed
CVE-2023-20864
was published
Apr 20, 2023
Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms...
Critical
Unreviewed
CVE-2023-30076
was published
Apr 20, 2023
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which...
Critical
Unreviewed
CVE-2023-2131
was published
Apr 20, 2023
Cross-site Scripting in org.xwiki.commons:xwiki-commons-xml
Critical
CVE-2023-29528
was published
for
org.xwiki.commons:xwiki-commons-xml
(Maven)
Apr 20, 2023
This vulnerability allows remote attackers to bypass authentication on affected installations of...
Critical
Unreviewed
CVE-2023-27350
was published
Apr 20, 2023
PowerJob vulnerable to remote code execution
Critical
CVE-2023-29926
was published
for
tech.powerjob:powerjob
(Maven)
Apr 20, 2023
An issue was discovered in ONOS 2.5.1. An intent with an uppercase letter in a device ID shows...
Critical
Unreviewed
CVE-2022-29604
was published
Apr 20, 2023
An issue was discovered in ONOS 2.5.1. An intent with a large port number shows the CORRUPT state...
Critical
Unreviewed
CVE-2022-29606
was published
Apr 20, 2023
Mattermost fails to invalidate existing authorization codes when deauthorizing an OAuth2 app,...
Critical
Unreviewed
CVE-2023-2193
was published
Apr 20, 2023
Buffer Overflow vulnerability in Qihoo 360 Chrome v13.0.2170.0 allows attacker to escalate...
Critical
Unreviewed
CVE-2021-33970
was published
Apr 20, 2023
The Flexi Classic and Flexi Soft Gateways SICK UE410-EN3 FLEXI ETHERNET GATEW., SICK UE410-EN1...
Critical
Unreviewed
CVE-2023-23451
was published
Apr 20, 2023
Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin
Critical
CVE-2023-22621
was published
for
@strapi/plugin-email
(npm)
Apr 19, 2023
In OnWakelockReleased of attribution_processor.cc, there is a use after free that could lead to...
Critical
Unreviewed
CVE-2023-21096
was published
Apr 19, 2023
Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows...
Critical
Unreviewed
CVE-2021-33975
was published
Apr 19, 2023
Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate...
Critical
Unreviewed
CVE-2021-33972
was published
Apr 19, 2023
Code injection via unescaped translations in xwiki-platform
Critical
CVE-2023-29510
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Apr 19, 2023
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who...
Critical
Unreviewed
CVE-2023-2136
was published
Apr 19, 2023
A deserialization vulnerability in the destruct() function of Laravel v8.5.9 allows attackers to...
Critical
Unreviewed
CVE-2021-28254
was published
Apr 19, 2023
A CWE-129: Improper validation of an array index vulnerability exists where a specially...
Critical
Unreviewed
CVE-2023-28004
was published
Apr 19, 2023
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow...
Critical
Unreviewed
CVE-2023-29411
was published
Apr 18, 2023
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists...
Critical
Unreviewed
CVE-2023-25549
was published
Apr 18, 2023
A CWE-78: Improper Handling of Case Sensitivity vulnerability exists that could cause remote...
Critical
Unreviewed
CVE-2023-29412
was published
Apr 18, 2023
ProTip!
Advisories are also available from the
GraphQL API