GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
434 advisories
Filter by severity
Typo3 API XSS Vulnerabilities
Moderate
CVE-2012-1608
was published
for
typo3/cms
(Composer)
May 17, 2022
Silverstripe CMS Arbitrary Code Execution
Moderate
CVE-2011-4962
was published
for
silverstripe/cms
(Composer)
May 17, 2022
Apache Libcloud vulnerable to certificate impersonation
Moderate
CVE-2012-3446
was published
for
apache-libcloud
(pip)
May 17, 2022
OpenID4Java does not verify that Attribute Exchange (AX) information is signed
Moderate
CVE-2011-4314
was published
for
org.openid4java:openid4java
(Maven)
May 17, 2022
DotNetNuke (DNN) Open redirect vulnerability
Moderate
CVE-2013-7335
was published
for
DotNetNuke.Core
(NuGet)
May 17, 2022
GitLab Grit Gem for Ruby contains a flaw allowing arbitrary commands to be executed
Moderate
CVE-2013-4489
was published
for
gitlab-grit
(RubyGems)
May 17, 2022
OpenStack Image Registry and Delivery Service (Glance) Improper Input Validation vulnerability
Moderate
CVE-2014-0162
was published
for
glance
(pip)
May 17, 2022
Cobbler vulnerable to code injection via unsafe YAML loading
Moderate
CVE-2011-4953
was published
for
cobbler
(pip)
May 17, 2022
XML External Entity Reference in RESTEasy
Moderate
CVE-2014-7839
was published
for
org.jboss.resteasy:resteasy-jaxrs
(Maven)
May 17, 2022
TYPO3 allows remote attackers to embed Flash videos from external domain
Moderate
CVE-2015-8760
was published
for
typo3/cms
(Composer)
May 17, 2022
PyWBEM TOCTOU vulnerability in certificate validation
Moderate
CVE-2013-6444
was published
for
pywbem
(pip)
May 17, 2022
Denial of service in Apache Struts
Moderate
CVE-2016-3093
was published
for
ognl:ognl
(Maven)
May 17, 2022
Drupal Denial of service via transliterate mechanism
Moderate
CVE-2016-9452
was published
for
drupal/core
(Composer)
May 17, 2022
phpMyAdmin Improper Input Validation
Moderate
CVE-2016-2562
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Improper Input Validation in Apache ActiveMQ
Moderate
CVE-2015-6524
was published
for
org.apache.activemq:activemq-broker
(Maven)
May 17, 2022
Open redirect in Apache Struts
Moderate
CVE-2013-2248
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
TYPO3 OpenID extension Open redirect vulnerability
Moderate
CVE-2013-7079
was published
for
friendsoftypo3/openid
(Composer)
May 17, 2022
XMPP Clients User Impersonation Vulnerability in Movim Moxl
Moderate
CVE-2017-5605
was published
for
movim/moxl
(Composer)
May 17, 2022
Laravel does not properly constrain the host portion of a password-reset URL
Moderate
CVE-2017-9303
was published
for
illuminate/auth
(Composer)
May 17, 2022
phpMyAdmin DoS Vulnerability
Moderate
CVE-2016-6623
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Denial of Service (DoS)
Moderate
CVE-2016-9860
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Apache Struts vulnerable to possible DoS attack when using URLValidator
Moderate
CVE-2016-4465
was published
for
org.apache.struts:struts2-core
(Maven)
May 17, 2022
Improper Input Validation in OpenSymphony XWork
Moderate
CVE-2008-6504
was published
for
com.opensymphony:xwork
(Maven)
May 17, 2022
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
Moderate
CVE-2011-0986
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API