GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,900
Maven
5,000+
npm
4,552
NuGet
786
pip
4,287
Pub
12
RubyGems
979
Rust
1,110
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,801 advisories
Filter by severity
Admidio Improper Access Control vulnerability
Low
CVE-2023-3303
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
RaspAP raspap-webgui Command Injection vulnerability
High
CVE-2023-30260
was published
for
billz/raspap-webgui
(Composer)
Jun 23, 2023
Apache StreamPipes Improper Privilege Management vulnerability
High
CVE-2023-31469
was published
for
org.apache.streampipes:streampipes-parent
(Maven)
Jun 23, 2023
Dynamic Linq vulnerable to remote code execution
Critical
CVE-2023-32571
was published
for
System.Linq.Dynamic.Core
(NuGet)
Jun 22, 2023
Moodle vulnerable to Cross-site Scripting
Moderate
CVE-2023-35131
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Moodle vulnerable to Server Side Request Forgery
High
CVE-2023-35133
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Moodle vulnerable to SQL Injection
Moderate
CVE-2023-35132
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Grafana vulnerable to Authentication Bypass by Spoofing
Critical
CVE-2023-3128
was published
for
github.com/grafana/grafana
(Go)
Jun 22, 2023
cyfs-base vulnerable to misaligned pointer dereference in `ChunkId::new`
Moderate
GHSA-g753-ghr7-q33w
was published
for
cyfs-base
(Rust)
Jun 22, 2023
Duplicate Advisory: Cosmos "Barberry" vulnerability in github.com/cosmos/cosmos-sdk
Moderate
GHSA-w44m-8mv2-v78h
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jun 22, 2023
•
withdrawn
Shescape potential environment variable exposure on Windows with CMD
Low
CVE-2023-35931
was published
for
shescape
(npm)
Jun 22, 2023
Vaadin vulnerable to possible information disclosure in non visible components.
Moderate
CVE-2023-25499
was published
for
com.vaadin:flow-server
(Maven)
Jun 22, 2023
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
Low
CVE-2023-25500
was published
for
com.vaadin:flow-server
(Maven)
Jun 22, 2023
FastAsyncWorldEdit vulnerable to Uncontrolled Resource Consumption
Moderate
CVE-2023-35925
was published
for
com.fastasyncworldedit:FastAsyncWorldEdit-Bukkit
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in DeleteApplication page
Critical
CVE-2023-35161
was published
for
org.xwiki.platform:xwiki-platform-appwithinminutes-ui
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via back and xcontinue parameters in resubmit template
Critical
CVE-2023-35160
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in deletespace template
Critical
CVE-2023-35159
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in restore template
Critical
CVE-2023-35158
was published
for
org.xwiki.platform:xwiki-platform-flamingo-skin-resources
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via delattachment action
High
CVE-2023-35157
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Jun 22, 2023
XWiki Platform vulnerable to reflected cross-site scripting via xredirect parameter in delete template
Critical
CVE-2023-35156
was published
for
org.xwiki.platform:xwiki-platform-flamingo-skin-resources
(Maven)
Jun 22, 2023
Flask-AppBuilder vulnerable to possible disclosure of sensitive information on user error
Moderate
CVE-2023-34110
was published
for
Flask-AppBuilder
(pip)
Jun 22, 2023
org.nokogiri:nekohtml vulnerable to Uncontrolled Resource Consumption
High
CVE-2022-24839
was published
for
org.nokogiri:nekohtml
(Maven)
Jun 22, 2023
fuadmin vulnerable to insecure file upload
Critical
CVE-2023-36097
was published
for
funadmin/funadmin
(Composer)
Jun 22, 2023
Casdoor Cross-Site Request Forgery vulnerability
Moderate
CVE-2023-34927
was published
for
github.com/casdoor/casdoor
(Go)
Jun 22, 2023
laravel-s vulnerable to Local File Inclusion
Critical
CVE-2023-29931
was published
for
hhxsv5/laravel-s
(Composer)
Jun 22, 2023
ProTip!
Advisories are also available from the
GraphQL API