GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,128 advisories
Filter by severity
Apache StreamPark Improper Input Validation vulnerability
Critical
CVE-2022-46365
was published
for
org.apache.streampark:streampark
(Maven)
Jul 6, 2023
Apache Zeppelin Improper Input Validation vulnerability
Moderate
CVE-2021-28655
was published
for
org.apache.zeppelin:zeppelin
(Maven)
Jul 6, 2023
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
High
CVE-2023-34457
was published
for
MechanicalSoup
(pip)
Jul 5, 2023
Apache Any23 vulnerable to excessive memory usage
Moderate
CVE-2023-34150
was published
for
org.apache.any23:apache-any23
(Maven)
Jul 5, 2023
kube-apiserver vulnerable to policy bypass
Moderate
CVE-2023-2727
was published
for
k8s.io/kubernetes
(Go)
Jul 3, 2023
Kubernetes mountable secrets policy bypass
Moderate
CVE-2023-2728
was published
for
k8s.io/kubernetes
(Go)
Jul 3, 2023
Apache Airflow Hive Provider Beeline remote code execution with Principal
Critical
CVE-2023-35797
was published
for
apache-airflow-providers-apache-hive
(pip)
Jul 3, 2023
Apache Airflow JDBC Provider Improper Input Validation vulnerability
High
CVE-2023-22886
was published
for
apache-airflow-providers-jdbc
(pip)
Jun 29, 2023
Apache Airflow ODBC Provider, Apache Airflow MSSQL Provider Improper Input Validation vulnerability
Moderate
CVE-2023-35798
was published
for
apache-airflow-providers-microsoft-mssql
(pip)
Jun 27, 2023
Vega's validators able to submit duplicate transactions
Moderate
CVE-2023-35163
was published
for
code.vegaprotocol.io/vega
(Go)
Jun 20, 2023
Grav Server-side Template Injection (SSTI) via Twig Default Filters
High
CVE-2023-34448
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Magento Open Source affected by Improper Input Validation
Low
CVE-2023-29293
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Gradio vulnerable to arbitrary file read and proxying of arbitrary URLs
Moderate
CVE-2023-34239
was published
for
gradio
(pip)
Jun 9, 2023
avo possible unsafe reflection / partial DoS vulnerability
High
CVE-2023-34102
was published
for
avo
(RubyGems)
Jun 6, 2023
mx-chain-go does not treat invalid transaction with wrong username correctly
High
CVE-2023-33964
was published
for
github.com/multiversx/mx-chain-go
(Go)
Jun 2, 2023
keep-module-latest vulnerable to Command Injection due to missing input sanitization
High
CVE-2023-26128
was published
for
keep-module-latest
(npm)
May 27, 2023
Ingress-nginx `path` sanitization can be bypassed with newline character
Moderate
CVE-2021-25748
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2023
Synapse Outgoing federation to specific hosts can be disabled by sending malicious invites
Moderate
CVE-2023-32323
was published
for
matrix-synapse
(pip)
May 24, 2023
Ckan remote code execution and private information access via crafted resource ids
Critical
CVE-2023-32321
was published
for
ckan
(pip)
May 24, 2023
Insufficient validation when decoding a Socket.IO packet
Moderate
CVE-2023-32695
was published
for
socket.io-parser
(npm)
May 23, 2023
Invalid push request payload crashes Parse Server
Moderate
CVE-2023-32688
was published
for
parse-server-push-adapter
(npm)
May 22, 2023
Apache Sling Commons JSON bundle vulnerable to Improper Input Validation
Critical
CVE-2022-47937
was published
for
org.apache.sling:org.apache.sling.commons.json
(Maven)
May 15, 2023
Apache OpenMeetings vulnerable to remote code execution via null-bye injection
High
CVE-2023-29246
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 12, 2023
Improper random reading in CIRCL
Moderate
CVE-2023-1732
was published
for
github.com/cloudflare/circl
(Go)
May 11, 2023
VTAdmin users that can create shards can deny access to other functions
Moderate
CVE-2023-29195
was published
for
vitess.io/vitess
(Go)
May 11, 2023
ProTip!
Advisories are also available from the
GraphQL API