GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
460 advisories
Filter by severity
Improper Input Validation in Apache Unomi
High
CVE-2020-11975
was published
for
org.apache.unomi:unomi
(Maven)
Feb 9, 2022
Improper Input Validation in Keycloak
High
CVE-2020-1714
was published
for
org.keycloak:keycloak-common
(Maven)
Feb 9, 2022
Server-side request forgery (SSRF) in Apache Batik
High
CVE-2019-17566
was published
for
org.apache.xmlgraphics:batik
(Maven)
Feb 9, 2022
Server-side request forgery (SSRF) in Apache XmlGraphics Commons
High
CVE-2020-11988
was published
for
org.apache.xmlgraphics:xmlgraphics-commons
(Maven)
Feb 9, 2022
Validation bypass in frourio-express
High
CVE-2022-23624
was published
for
frourio-express
(npm)
Feb 7, 2022
Lookup operations do not take into account wildcards in SpiceDB
High
CVE-2022-21646
was published
for
github.com/authzed/spicedb
(Go)
Jan 13, 2022
Access to restricted PHP code by dynamic static class access in smarty
High
CVE-2021-21408
was published
for
smarty/smarty
(Composer)
Jan 12, 2022
Pipenv's requirements.txt parsing allows malicious index url in comments
High
CVE-2022-21668
was published
for
pipenv
(pip)
Jan 12, 2022
Improper Input Validation in Parquet-MR
High
CVE-2021-41561
was published
for
org.apache.parquet:parquet
(Maven)
Jan 6, 2022
Server-side request forgery (SSRF) in Apache Batik
High
CVE-2020-11987
was published
for
org.apache.xmlgraphics:batik-svgbrowser
(Maven)
Jan 6, 2022
Sandbox Bypass in Apache Velocity Engine
High
CVE-2020-13936
was published
for
org.apache.velocity:velocity
(Maven)
Jan 6, 2022
Incorrect sanitisation function leads to `XSS` in mermaid
High
CVE-2021-43861
was published
for
mermaid
(npm)
Jan 6, 2022
Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion
High
CVE-2021-45105
was published
for
org.apache.logging.log4j:log4j-core
(Maven)
Dec 18, 2021
YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number
High
CVE-2021-4111
was published
for
yetiforce/yetiforce-crm
(Composer)
Dec 16, 2021
Improper Input Validation in is-email
High
CVE-2021-36716
was published
for
is-email
(npm)
Dec 10, 2021
Improper Input Validation in xdLocalStorage
High
CVE-2015-9545
was published
for
xdLocalStorage
(npm)
Dec 9, 2021
Improper Input Validation in xdLocalStorage
High
CVE-2015-9544
was published
for
xdLocalStorage
(npm)
Dec 9, 2021
Improper Input Validation in fruity
High
CVE-2021-43620
was published
for
fruity
(Rust)
Nov 16, 2021
NUL character in ROA causes OctoRPKI to crash
High
CVE-2021-3910
was published
for
github.com/cloudflare/cfrpki
(Go)
Nov 10, 2021
ProTip!
Advisories are also available from the
GraphQL API