GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,405
Maven
5,000+
npm
5,000+
NuGet
882
pip
4,641
Pub
13
RubyGems
1,026
Rust
1,209
Swift
53
Unreviewed advisories
All unreviewed
5,000+
28,407 advisories
Filter by severity
Onnx Directory Traversal vulnerability
High
CVE-2024-27318
was published
for
onnx
(pip)
Feb 23, 2024
Onnx Out-of-bounds Read vulnerability
Moderate
CVE-2024-27319
was published
for
onnx
(pip)
Feb 23, 2024
Apache DolphinScheduler vulnerable to arbitrary JavaScript execution as root for authenticated users
High
CVE-2024-23320
was published
for
org.apache.dolphinscheduler:dolphinscheduler-master
(Maven)
Feb 23, 2024
`@backstage/backend-common` vulnerable to path traversal through symlinks
High
CVE-2024-26150
was published
for
@backstage/backend-common
(npm)
Feb 23, 2024
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
High
CVE-2024-22243
was published
for
org.springframework:spring-web
(Maven)
Feb 23, 2024
Appwrite Directory Traversal vulnerability
High
CVE-2022-25377
was published
for
appwrite/server-ce
(Composer)
Feb 23, 2024
Gradio apps vulnerable to timing attacks to guess password
Moderate
CVE-2024-1729
was published
for
gradio
(pip)
Feb 22, 2024
Label Studio vulnerable to Cross-site Scripting if `<Choices>` or `<Labels>` are used in labeling config
Moderate
CVE-2024-26152
was published
for
label-studio
(pip)
Feb 22, 2024
pypqc private key retrieval vulnerability
High
GHSA-rc4p-p3j9-6577
was published
for
pypqc
(pip)
Feb 22, 2024
Potentially untrusted input is rendered as HTML in final output
High
CVE-2024-26151
was published
for
mjml
(pip)
Feb 22, 2024
User with ci:ReadAction permissions and write permissions to one path in a repository may copy objects from any path in the repository
Moderate
GHSA-fvv5-h29g-f6w5
was published
for
github.com/treeverse/lakefs
(Go)
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Site search Feature
Moderate
CVE-2023-44379
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
Moderate
CVE-2023-51450
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
Moderate
CVE-2024-26128
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
Helm's Missing YAML Content Leads To Panic
High
CVE-2024-26147
was published
for
helm.sh/helm/v3
(Go)
Feb 22, 2024
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
Critical
GHSA-97m3-52wr-xvv2
was published
for
phenx/php-svg-lib
(Composer)
Feb 22, 2024
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25876
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25875
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25874
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
Apache Answer Cross-site Scripting vulnerability
Moderate
CVE-2024-23349
was published
for
github.com/apache/incubator-answer
(Go)
Feb 22, 2024
Apache Answer Race Condition vulnerability
Moderate
CVE-2024-26578
was published
for
github.com/apache/incubator-answer
(Go)
Feb 22, 2024
Apache Answer Unrestricted Upload of File with Dangerous Type vulnerability
High
CVE-2024-22393
was published
for
github.com/apache/incubator-answer
(Go)
Feb 22, 2024
Path Traversal in TYPO3 Core
Moderate
GHSA-gj48-w74w-8gvm
was published
for
typo3/cms
(Composer)
Feb 22, 2024
ProTip!
Advisories are also available from the
GraphQL API