GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,635 advisories
Filter by severity
powermail extension for TYPO3 has Cross-site Scripting vulnerability
Low
CVE-2012-5889
was published
for
in2code/powermail
(Composer)
May 17, 2022
Typo3 Function Menu API XSS Vulnerability
Low
CVE-2012-6148
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend History Module Vulnerable to XSS
Low
CVE-2012-6145
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend API XSS Vulnerability
Low
CVE-2012-6147
was published
for
typo3/cms
(Composer)
May 17, 2022
OpenStack Glance is vulnerable to Exposure of Sensitive Information
Low
CVE-2013-1840
was published
for
glance
(pip)
May 17, 2022
Static Methods since 2007 (div2007) extension for TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5100
was published
for
jambagecom/div2007
(Composer)
May 17, 2022
Static Info Tables (static_info_tables) extension TYPO3 vulnerable to Cross-site Scripting
Low
CVE-2013-5323
was published
for
sjbr/static-info-tables
(Composer)
May 17, 2022
Jenkins allows Cross-Site Scripting (XSS) in User Configuration
Low
CVE-2013-5573
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 17, 2022
TYPO3 Cross-Site Scripting (XSS) vulnerabilities in Content Editing Wizards component
Low
CVE-2013-7074
was published
for
typo3/cms
(Composer)
May 17, 2022
TYPO3 Cross-site scripting (XSS) vulnerability in the Extbase Framework
Low
CVE-2013-7078
was published
for
typo3/cms-core
(Composer)
May 17, 2022
RPLY Predictable Tmpfile Names Allows Cache Spoofing
Low
CVE-2014-1604
was published
for
RPLY
(pip)
May 17, 2022
pyxdg Arbitrary File Overwrite via Race Condition
Low
CVE-2014-1624
was published
for
pyxdg
(pip)
May 17, 2022
python-keystoneclient unsecure user password update
Low
CVE-2013-2013
was published
for
python-keystoneclient
(pip)
May 17, 2022
Exposure of Sensitive Information in Jenkins Datadog plugin
Low
CVE-2017-1000114
was published
for
org.datadog.jenkins.plugins:datadog
(Maven)
May 17, 2022
Insecure temporary file usage in Jenkins Git Client Plugin
Low
CVE-2017-1000242
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
May 17, 2022
python-keystoneclient vulnerable to context confusion in Keystone auth_token middleware
Low
CVE-2014-0105
was published
for
python-keystoneclient
(pip)
May 17, 2022
OpenStack Heat template URL information leakage
Low
CVE-2014-3801
was published
for
openstack-heat
(pip)
May 14, 2022
Jenkins Reverse Proxy Auth Plugin allows attackers with local file system access to obtain a list of authorities for logged in users
Low
CVE-2018-1000150
was published
for
org.jenkins-ci.plugins:reverse-proxy-auth-plugin
(Maven)
May 14, 2022
Jenkins GitHub Pull Request Builder Plugin
Low
CVE-2018-1000143
was published
for
org.jenkins-ci.plugins:ghprb
(Maven)
May 14, 2022
Jenkins GitHub Pull Request Builder Plugin credential capture vulnerability
Low
CVE-2018-1000186
was published
for
org.jenkins-ci.plugins:ghprb
(Maven)
May 14, 2022
Jenkins meliora-testlab Plugin allows attackers with file system access to Jenkins master to obtain API key
Low
CVE-2018-1999031
was published
for
org.jenkins-ci.plugins:meliora-testlab
(Maven)
May 14, 2022
Libcloud does not properly scrub data when destroying a DigitalOcean node
Low
CVE-2013-6480
was published
for
apache-libcloud
(pip)
May 14, 2022
Alkacon OpenCMS XSS via homelink, workplaceresource, mode and query parameters
Low
CVE-2015-2351
was published
for
org.opencms:opencms-core
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API