GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,636
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,629 advisories
Filter by severity
Cross-site scripting in Apache Syncome EndUser
Low
CVE-2019-17557
was published
for
org.apache.syncope.client:syncope-client-enduser
(Maven)
Jan 6, 2022
devices resource list treated as a blacklist by default
Low
GHSA-g54h-m393-cpwq
was published
for
github.com/opencontainers/runc
(Go)
Dec 20, 2021
Regular Expression Denial of Service (ReDoS) in jsx-slack
Low
CVE-2021-43838
was published
for
jsx-slack
(npm)
Dec 17, 2021
Inability to de-op players if listed in ops.txt with non-lowercase letters
Low
GHSA-j5qg-w9jg-3wg3
was published
for
pocketmine/pocketmine-mp
(Composer)
Dec 16, 2021
Open Redirect in Flask-Security-Too
Low
GHSA-gxjj-f44v-qm94
was published
for
Flask-Security-Too
(pip)
Dec 14, 2021
•
withdrawn
Cross-Site Request Forgery in remdex/livehelperchat
Low
CVE-2021-4049
was published
for
remdex/livehelperchat
(Composer)
Dec 10, 2021
bookstack is vulnerable to Cross-Site Request Forgery (CSRF)
Low
CVE-2021-3944
was published
for
ssddanbrown/bookstack
(Composer)
Dec 3, 2021
Use of Sha-1 in tusdotnet
Low
CVE-2021-44150
was published
for
tusdotnet
(NuGet)
Nov 29, 2021
•
withdrawn
Clarify Content-Type handling
Low
CVE-2021-41190
was published
for
github.com/opencontainers/distribution-spec
(Go)
Nov 18, 2021
Ambiguous OCI manifest parsing
Low
GHSA-5j5w-g665-5m35
was published
for
github.com/containerd/containerd
(Go)
Nov 18, 2021
Clarify `mediaType` handling
Low
GHSA-77vh-xpmg-72qh
was published
for
github.com/opencontainers/image-spec
(Go)
Nov 18, 2021
ERC1155Supply vulnerability in OpenZeppelin Contracts
Low
GHSA-wmpv-c2jp-j2xg
was published
for
@openzeppelin/contracts
(npm)
Nov 15, 2021
snipe-it is vulnerable to Cross-site Scripting
Low
CVE-2021-3938
was published
for
snipe/snipe-it
(Composer)
Nov 15, 2021
Cross-site Scripting in bootstrap-table
Low
CVE-2021-23472
was published
for
bootstrap-table
(npm)
Nov 8, 2021
Cross-Site Request Forgery in firefly-iii
Low
CVE-2021-3901
was published
for
grumpydictator/firefly-iii
(Composer)
Oct 28, 2021
pterodactyl/panel CSRF allowing an external page to trigger a user logout event
Low
CVE-2021-41176
was published
for
pterodactyl/panel
(Composer)
Oct 25, 2021
Puma with proxy which forwards LF characters as line endings could allow HTTP request smuggling
Low
CVE-2021-41136
was published
for
puma
(RubyGems)
Oct 12, 2021
Hashicorp Vault Privilege Escalation Vulnerability
Low
CVE-2021-41802
was published
for
github.com/hashicorp/vault
(Go)
Oct 12, 2021
MD5 hash support in github.com/foxcpp/maddy
Low
GHSA-qh54-9vc5-m9fg
was published
for
github.com/foxcpp/maddy
(Go)
Oct 12, 2021
Path traversal when using `preview-docs` when working dir contains files with question mark `?` in name
Low
GHSA-q324-q795-2q5p
was published
for
@redocly/openapi-cli
(npm)
Oct 12, 2021
Confused Deputy in Kubernetes
Low
CVE-2021-25740
was published
for
k8s.io/kubernetes
(Go)
Sep 21, 2021
Improper Input Validation in Firefly III
Low
CVE-2019-14671
was published
for
grumpydictator/firefly-iii
(Composer)
Sep 8, 2021
Command injection in @diez/generation
Low
CVE-2021-32830
was published
for
@diez/generation
(npm)
Sep 2, 2021
Use of a Broken or Risky Cryptographic Algorithm
Low
CVE-2021-27913
was published
for
mautic/core
(Composer)
Sep 1, 2021
Adding a private/unlisted room to a community exposes room metadata in an unauthorised manner.
Low
CVE-2021-39163
was published
for
matrix-synapse
(pip)
Sep 1, 2021
ProTip!
Advisories are also available from the
GraphQL API