GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,645
Maven
5,000+
npm
4,271
NuGet
760
pip
4,065
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,635 advisories
Filter by severity
pyca/cryptography's wheels include vulnerable OpenSSL
Low
GHSA-jm77-qphf-c4w8
was published
for
cryptography
(pip)
Aug 1, 2023
Silverstripe Framework: Members with no password can be created and bypass custom login forms
Low
CVE-2023-32302
was published
for
silverstripe/framework
(Composer)
Jul 31, 2023
Denial of service from large image
Low
CVE-2023-37900
was published
for
github.com/crossplane/crossplane
(Go)
Jul 28, 2023
Cross-site Scripting in Mingsoft MCMS
Low
CVE-2023-3990
was published
for
net.mingsoft:ms-mcms
(Maven)
Jul 28, 2023
Unsoundness in `intern` methods on `intaglio` symbol interners
Low
GHSA-gch5-hwqf-mxhp
was published
for
intaglio
(Rust)
Jul 27, 2023
Secret displayed without masking by Chef Identity Plugin
Low
CVE-2023-39155
was published
for
org.jenkins-ci.plugins:chef-identity
(Maven)
Jul 26, 2023
Information Disclosure due to Out-of-scope Site Resolution
Low
CVE-2023-38499
was published
for
typo3/cms-core
(Composer)
Jul 25, 2023
Potential denial of service after connection migration
Low
GHSA-rfhg-rjfp-9q8q
was published
for
s2n-quic
(Rust)
Jul 24, 2023
RuoYi vulnerable to Cross-site Scripting
Low
CVE-2023-3815
was published
for
com.ruoyi:ruoyi
(Maven)
Jul 21, 2023
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel
Low
CVE-2023-3299
was published
for
github.com/hashicorp/nomad
(Go)
Jul 20, 2023
Potential leak of credentials in Micro Focus Dimensions CM Jenkins Plugin
Low
CVE-2023-32263
was published
for
org.jenkins-ci.plugins:dimensionsscm
(Maven)
Jul 19, 2023
Fides Webserver Vulnerable to SVG Bomb File Uploads
Low
CVE-2023-37481
was published
for
ethyca-fides
(pip)
Jul 18, 2023
Fides Webserver Vulnerable to Zip Bomb File Uploads
Low
CVE-2023-37480
was published
for
ethyca-fides
(pip)
Jul 18, 2023
topgrade Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Low
GHSA-f2wx-xjfw-xjv6
was published
for
topgrade
(Rust)
Jul 17, 2023
Vendure Cross Site Request Forgery vulnerability impacting all API requests
Low
GHSA-h9wq-xcqx-mqxm
was published
for
@vendure/core
(npm)
Jul 11, 2023
Eclipse Jetty XmlParser allows arbitrary DOCTYPE declarations
Low
GHSA-58qw-p7qm-5rvh
was published
for
org.eclipse.jetty:jetty-xml
(Maven)
Jul 10, 2023
sweetalert2 contains potentially undesirable behavior
Low
GHSA-mrr8-v49w-3333
was published
for
sweetalert2
(npm)
Jul 10, 2023
Apache Camel information exposure vulnerability
Low
CVE-2023-34442
was published
for
org.apache.camel:camel-jira
(Maven)
Jul 10, 2023
Winter CMS stored XSS through privileged upload of SVG file
Low
CVE-2023-37269
was published
for
wintercms/winter
(Composer)
Jul 7, 2023
Stylelint has vulnerability in semver dependency
Low
GHSA-f7xj-rg7h-mc87
was published
for
stylelint
(npm)
Jul 7, 2023
•
withdrawn
Pipelines do not validate child UIDs
Low
CVE-2023-37264
was published
for
github.com/tektoncd/pipeline
(Go)
Jul 7, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Graylog vulnerable to insecure source port usage for DNS queries
Low
CVE-2023-41045
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Graylog user session is still usable after logout
Low
CVE-2023-41041
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Magento Open Source allows Cross-Site Scripting (XSS)
Low
CVE-2023-22249
was published
for
magento/community-edition
(Composer)
Jul 6, 2023
ProTip!
Advisories are also available from the
GraphQL API