Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

28,101 advisories

Loading
Stimulsoft Dashboard.JS Cross Site Scripting vulnerability Moderate
CVE-2024-24397 was published for stimulsoft-dashboards-js (npm) Feb 5, 2024
Duplicate Advisory: FastAPI Content-Type Header ReDoS High
GHSA-qf9m-vfgh-m389 was published for fastapi (pip) Feb 5, 2024 withdrawn
nicecatch2000 Credited to nicecatch2000, huonw, garyd203, and levpachmanov huonw huonw
garyd203 garyd203 levpachmanov levpachmanov
Duplicate Advisory: Starlette Content-Type Header ReDoS High
GHSA-93gm-qmq6-w238 was published for starlette (pip) Feb 5, 2024 withdrawn
tiangolo Credited to tiangolo and nicecatch2000 nicecatch2000 nicecatch2000
Yarn untrusted search path vulnerability High
CVE-2021-4435 was published for yarn (npm) Feb 4, 2024
.NET Information Disclosure Vulnerability Moderate
CVE-2022-34716 was published for Microsoft.AspNetCore.App.Runtime.linux-arm (NuGet) Feb 3, 2024
noymaor Credited to noymaor
Zmarkdown Server-Side Request Forgery (SSRF) in remark-download-images Moderate
GHSA-mf74-qq7w-6j7v was published for remark-images-download (npm) Feb 3, 2024
gustavi Credited to gustavi
Local File Inclusion vulnerability in zmarkdown Low
GHSA-mq6v-w35g-3c97 was published for zmarkdown (npm) Feb 3, 2024
gustavi Credited to gustavi
Nervos CKB Permit load cell data from memory Moderate
GHSA-29c2-65rj-h343 was published for ckb (Rust) Feb 3, 2024
Nervos CKB Pool does not remove the conflicting transactions from the statistics Moderate
GHSA-h4c3-5275-vrmg was published for ckb (Rust) Feb 3, 2024
Use after free in libpulse-binding Moderate
CVE-2018-25001 was published for libpulse-binding (Rust) Feb 3, 2024
github-slug-action use of `set-env` Runner commands which are processed via stdout Moderate
GHSA-7f32-hm4h-w77q was published for rlespinasse/github-slug-action (GitHub Actions) Feb 3, 2024
hsblhsn Credited to hsblhsn and rlespinasse rlespinasse rlespinasse
Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic result Critical
GHSA-q73f-w3h7-7wcc was published for ckb (Rust) Feb 3, 2024
Nervos CKB Snappy decompress length can be very large and causes out of memory error High
GHSA-3gjh-29fv-8hr6 was published for ckb (Rust) Feb 3, 2024
quake Credited to quake
Nervos CKB Panic on malformed input High
GHSA-wjxc-pjx9-4wvm was published for ckb (Rust) Feb 3, 2024
quake Credited to quake
Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only Low
GHSA-vjg6-93fv-qv64 was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd embed auto compaction retention negative value causing a compaction loop or a crash Low
GHSA-pm3m-32r3-7mfh was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd Gateway TLS endpoint validation only confirms TCP reachability Moderate
GHSA-j86v-2vjr-fg8f was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd pkg Insecure ciphers are allowed by default Low
GHSA-5x4g-q5rc-36jp was published for go.etcd.io/etcd/client/pkg/v3 (Go) Feb 3, 2024
Nervos CKB node panics when processing a block which parent timestamp is too new High
GHSA-hjqq-29pw-96wj was published for ckb (Rust) Feb 2, 2024
Nervos CKB BlockTimeTooNew should not be considered as invalid block Moderate
GHSA-r9rv-9mh8-pxf4 was published for ckb (Rust) Feb 2, 2024
Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IP Low
GHSA-pr39-8257-fxc2 was published for ckb (Rust) Feb 2, 2024
Nervos CKB P2P DoS Attacks Critical
GHSA-84x2-2qv6-qg56 was published for ckb (Rust) Feb 2, 2024
PowerShell is subject to remote code execution vulnerability High
GHSA-jcmq-5rrv-j2g4 was published for PowerShell (NuGet) Feb 2, 2024
Nervos CKB Unaligned Pointer Dereference Moderate
GHSA-q669-2vfg-cxcg was published for ckb (Rust) Feb 2, 2024
PHPMailer Local file inclusion Moderate
CVE-2006-5734 was published for phpmailer/phpmailer (Composer) Feb 2, 2024
ProTip! Advisories are also available from the GraphQL API