GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,062 advisories
Filter by severity
Gophish vulnerable to Denial of Service via crafted payload involving autofocus
High
CVE-2022-45003
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
crewjam/saml vulnerable to Denial Of Service Via Deflate Decompression Bomb
High
CVE-2023-28119
was published
for
github.com/crewjam/saml
(Go)
Mar 22, 2023
Pimcore vulnerable to improper quoting of filters in Custom Reports
Moderate
CVE-2023-28438
was published
for
pimcore/pimcore
(Composer)
Mar 22, 2023
Pimcore Remote Code Execution vulnerability in Search function
Moderate
CVE-2023-1578
was published
for
pimcore/pimcore
(Composer)
Mar 22, 2023
Apache Tomcat vulnerable to Unprotected Transport of Credentials
Moderate
CVE-2023-28708
was published
for
org.apache.tomcat:tomcat-catalina
(Maven)
Mar 22, 2023
Jettison vulnerable to infinite recursion
High
CVE-2023-1436
was published
for
org.codehaus.jettison:jettison
(Maven)
Mar 22, 2023
dio vulnerable to CRLF injection with HTTP method string
High
CVE-2021-31402
was published
for
dio
(Pub)
Mar 21, 2023
cloudflared's Installer has Local Privilege Escalation Vulnerability
High
CVE-2023-1314
was published
for
github.com/cloudflare/cloudflared
(Go)
Mar 21, 2023
Frontier's modexp precompile is slow for even modulus
High
CVE-2023-28431
was published
for
pallet-evm-precompile-modexp
(Rust)
Mar 21, 2023
Sentry SDK leaks sensitive session information when `sendDefaultPII` is set to `True`
High
CVE-2023-28117
was published
for
sentry-sdk
(pip)
Mar 21, 2023
`cilium-cli` disables etcd authorization for clustermesh clusters
Moderate
CVE-2023-28114
was published
for
github.com/cilium/cilium-cli
(Go)
Mar 21, 2023
Xuxueli xxl-job allows attacker to obtain sensitive information via the pageList parameter
High
CVE-2023-27087
was published
for
com.xuxueli:xxl-job
(Maven)
Mar 21, 2023
weixin-python XML External Entity vulnerability
Critical
CVE-2018-25082
was published
for
weixin-python
(pip)
Mar 21, 2023
Teampass SQL Injection vulnerability
High
CVE-2023-1545
was published
for
nilsteampassnet/teampass
(Composer)
Mar 21, 2023
Answer has Observable Timing Discrepancy
Moderate
CVE-2023-1538
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Authentication Bypass by Capture-replay
Critical
CVE-2023-1537
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Business Logic Errors
Moderate
CVE-2023-1542
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer has Guessable CAPTCHA
Moderate
CVE-2023-1539
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-1536
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-1535
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer has Observable Response Discrepancy
Moderate
CVE-2023-1540
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Business Logic Errors
Low
CVE-2023-1541
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Answer vulnerable to Insufficient Session Expiration
High
CVE-2023-1543
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
CairoSVG improperly processes SVG files loaded from external resources
High
CVE-2023-27586
was published
for
CairoSVG
(pip)
Mar 20, 2023
kaml has potential denial of service while parsing input with anchors and aliases
High
CVE-2023-28118
was published
for
com.charleskorn.kaml:kaml
(Maven)
Mar 20, 2023
ProTip!
Advisories are also available from the
GraphQL API