Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

28,090 advisories

Loading
Nervos CKB Transaction which calls syscall load_cell_data_hash has nondeterministic result Critical
GHSA-q73f-w3h7-7wcc was published for ckb (Rust) Feb 3, 2024
Nervos CKB Snappy decompress length can be very large and causes out of memory error High
GHSA-3gjh-29fv-8hr6 was published for ckb (Rust) Feb 3, 2024
quake Credited to quake
Nervos CKB Panic on malformed input High
GHSA-wjxc-pjx9-4wvm was published for ckb (Rust) Feb 3, 2024
quake Credited to quake
Etcd auth Inaccurate logging of authentication attempts for users with CN-based auth only Low
GHSA-vjg6-93fv-qv64 was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd embed auto compaction retention negative value causing a compaction loop or a crash Low
GHSA-pm3m-32r3-7mfh was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd Gateway TLS endpoint validation only confirms TCP reachability Moderate
GHSA-j86v-2vjr-fg8f was published for go.etcd.io/etcd/v3 (Go) Feb 3, 2024
Etcd pkg Insecure ciphers are allowed by default Low
GHSA-5x4g-q5rc-36jp was published for go.etcd.io/etcd/client/pkg/v3 (Go) Feb 3, 2024
Nervos CKB node panics when processing a block which parent timestamp is too new High
GHSA-hjqq-29pw-96wj was published for ckb (Rust) Feb 2, 2024
Nervos CKB BlockTimeTooNew should not be considered as invalid block Moderate
GHSA-r9rv-9mh8-pxf4 was published for ckb (Rust) Feb 2, 2024
Nervos CKB DoS: Process exists when p2p discovery protocol receives unsupported peer IP Low
GHSA-pr39-8257-fxc2 was published for ckb (Rust) Feb 2, 2024
Nervos CKB P2P DoS Attacks Critical
GHSA-84x2-2qv6-qg56 was published for ckb (Rust) Feb 2, 2024
PowerShell is subject to remote code execution vulnerability High
GHSA-jcmq-5rrv-j2g4 was published for PowerShell (NuGet) Feb 2, 2024
Nervos CKB Unaligned Pointer Dereference Moderate
GHSA-q669-2vfg-cxcg was published for ckb (Rust) Feb 2, 2024
PHPMailer Local file inclusion Moderate
CVE-2006-5734 was published for phpmailer/phpmailer (Composer) Feb 2, 2024
PHPMailer Shell command injection High
CVE-2007-3215 was published for phpmailer/phpmailer (Composer) Feb 2, 2024
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm. High
CVE-2023-51838 was published for meshcentral (npm) Feb 2, 2024
Talos Linux ships runc vulnerable to the escape to the host attack High
GHSA-g5p6-327m-3fxx was published for github.com/siderolabs/talos (Go) Feb 2, 2024
Vyper's external calls can overflow return data to return input buffer Low
CVE-2024-24560 was published for vyper (pip) Feb 2, 2024
zobront Credited to zobront
Malicious input can provoke XSS when preserving comments Moderate
CVE-2024-23635 was published for org.owasp.antisamy:antisamy (Maven) Feb 2, 2024
spassarop Credited to spassarop, leeN, rbri, and davewichers leeN leeN
rbri rbri davewichers davewichers
Central Dogma Authentication Bypass Vulnerability via Session Leakage Critical
CVE-2024-1143 was published for com.linecorp.centraldogma:centraldogma-server (Maven) Feb 2, 2024
minwoox Credited to minwoox
Duplicate Advisory: Central Dogma Authentication Bypass Vulnerability via Session Leakage Moderate
GHSA-qfv2-3p2f-vg48 was published for com.linecorp.centraldogma:centraldogma-server (Maven) Feb 2, 2024 withdrawn
Dash apps vulnerable to Cross-site Scripting Moderate
CVE-2024-21485 was published for dash (npm) Feb 2, 2024
graingert Credited to graingert
Beetl Server-Side Template Injection vulnerability Critical
CVE-2024-22533 was published for com.ibeetl:beetl-core (Maven) Feb 2, 2024
yoshizawa-masatoshi Credited to yoshizawa-masatoshi
Bref vulnerable to Body Parsing Inconsistency in Event-Driven Functions Low
CVE-2024-24754 was published for bref/bref (Composer) Feb 1, 2024
smaury Credited to smaury
Bref Doesn't Support Multiple Value Headers in ApiGatewayFormatV2 Moderate
CVE-2024-24753 was published for bref/bref (Composer) Feb 1, 2024
smaury Credited to smaury and mnapoli mnapoli mnapoli
ProTip! Advisories are also available from the GraphQL API