GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,635 advisories
Filter by severity
Jenkins allows Cross-Site Scripting (XSS)
Low
CVE-2015-1813
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
Jenkins Vulnerable to Denial of Service (DoS)
Low
CVE-2015-1808
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
OpenStack Neutron Race condition vulnerability
Low
CVE-2015-5240
was published
for
neutron
(pip)
May 17, 2022
Jenkins Build Failure Analyzer Plugin allows Cross-Site Scripting (XSS)
Low
CVE-2013-6374
was published
for
com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer
(Maven)
May 17, 2022
ceph-deploy allows local users to obtain sensitive information by reading the file
Low
CVE-2015-3010
was published
for
ceph-deploy
(pip)
May 17, 2022
concrete5 vulnerable to Cross-site Scripting
Low
CVE-2015-3989
was published
for
concrete5/concrete5
(Composer)
May 17, 2022
phpMyAdmin cross-site scripting Vulnerability in Table or Column Names
Low
CVE-2014-4986
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value
Low
CVE-2013-5002
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Joomla! Cross-site Scripting vulnerability
Low
CVE-2013-5583
was published
for
joomla/joomla-cms
(Composer)
May 17, 2022
Salt uses weak permissions on the cache data
Low
CVE-2015-8034
was published
for
salt
(pip)
May 17, 2022
Improper Authentication in Apache Hadoop
Low
CVE-2013-2192
was published
for
org.apache.hadoop:hadoop-common
(Maven)
May 17, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat
Low
CVE-2013-2071
was published
for
org.apache.tomcat:tomcat
(Maven)
May 17, 2022
phpMyAdmin cookie-attribute injection
Low
CVE-2016-5702
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
typo3/cms-felogin Cross-site Scripting vulnerability
Low
CVE-2008-5656
was published
for
typo3/cms-felogin
(Composer)
May 17, 2022
TYPO3 Cross-site scripting (XSS) vulnerability in the click enlarge functionality
Low
CVE-2010-5097
was published
for
typo3/cms-frontend
(Composer)
May 17, 2022
TYPO3 Cross-site scripting (XSS) vulnerability in the FORM content object
Low
CVE-2010-5098
was published
for
typo3/cms-frontend
(Composer)
May 17, 2022
TYPO3 Cross-Site Scripting vulnerability in the Install Tool
Low
CVE-2010-5100
was published
for
typo3/cms-install
(Composer)
May 17, 2022
Symphony CMS vulnerable to Cross-site Scripting
Low
CVE-2011-4340
was published
for
symphonycms/symphony-2
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting vulnerability
Low
CVE-2011-4782
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Openstack Compute (Nova) Denial of service via network request that triggers large number of iptables rules
Low
CVE-2012-2101
was published
for
nova
(pip)
May 17, 2022
Typo3 Backend XSS Vulnerability
Low
CVE-2012-3528
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend Configuration XSS Vulnerability
Low
CVE-2012-3529
was published
for
typo3/cms
(Composer)
May 17, 2022
OpenStack Keystone intended authorization restrictions bypass
Low
CVE-2012-5571
was published
for
Keystone
(pip)
May 17, 2022
Basic SEO Features (seo_basics) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2012-5888
was published
for
b13/seo_basics
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API