Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

27,761 advisories

Loading
In Tenda AC15 V15.03.05.19, the function GetValue contains a stack-based buffer overflow... Critical Unreviewed
CVE-2023-30370 was published Apr 24, 2023
Tenda AC5 V15.03.06.28 is vulnerable to Buffer Overflow via the initWebs function. Critical Unreviewed
CVE-2023-30368 was published Apr 24, 2023
Tenda AC15 V15.03.05.19 is vulnerable to Buffer Overflow. Critical Unreviewed
CVE-2023-30369 was published Apr 24, 2023
In JetBrains Hub before 2023.1.15725 SSRF protection in Auth Module integration was missing Critical Unreviewed
CVE-2022-48477 was published Apr 24, 2023
Expo SDK has an OAuth vulnerability Critical
CVE-2023-28131 was published for expo (npm) Apr 24, 2023
hbabathe
Credited to hbabathe
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as... Critical Unreviewed
CVE-2023-23753 was published Apr 23, 2023
PowerJob vulnerable to incorrect access control Critical
CVE-2023-29924 was published for tech.powerjob:powerjob (Maven) Apr 21, 2023
achibear
Credited to achibear
IO FinNet tss-lib vulnerable to timing attack from non-constant time scalar multiplication Critical
CVE-2023-26556 was published for github.com/binance-chain/tss-lib (Go) Apr 21, 2023
A vulnerability, which was classified as critical, was found in MAXTECH MAX-G866ac 0.4... Critical Unreviewed
CVE-2023-2231 was published Apr 21, 2023
Improper Authorization in modoboa Critical
CVE-2023-2227 was published for modoboa (pip) Apr 21, 2023
XWiki Platform vulnerable to privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration Critical
CVE-2023-29525 was published for org.xwiki.platform:xwiki-platform-distribution-war (Maven) Apr 20, 2023
XWiki Platform vulnerable to code injection from account through AWM view sheet Critical
CVE-2023-29527 was published for org.xwiki.platform:xwiki-platform-appwithinminutes-ui (Maven) Apr 20, 2023
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode Critical
CVE-2023-29526 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Apr 20, 2023
XWiki Platform vulnerable to code injection from account through XWiki.SchedulerJobSheet Critical
CVE-2023-29524 was published for org.xwiki.platform:xwiki-platform-scheduler-ui (Maven) Apr 20, 2023
XWiki Platform vulnerable to code injection in display method used in user profiles Critical
CVE-2023-29523 was published for org.xwiki.platform:xwiki-platform-oldcore (Maven) Apr 20, 2023
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector Critical
CVE-2023-29516 was published for org.xwiki.platform:xwiki-platform-attachment-ui (Maven) Apr 20, 2023
XWiki vulnerable to Code Injection in template provider administration Critical
CVE-2023-29514 was published for org.xwiki.platform.applications:xwiki-application-administration (Maven) Apr 20, 2023
xwiki-platform-web-templates vulnerable to Eval Injection Critical
CVE-2023-29512 was published for org.xwiki.platform:xwiki-platform-web-templates (Maven) Apr 20, 2023
ProTip! Advisories are also available from the GraphQL API