GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
434 advisories
Filter by severity
Improper Input Validation in Apache CXF
Moderate
CVE-2017-12624
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
Improper Input Validation in Apache Santuario XML Security
Moderate
CVE-2014-8152
was published
for
org.apache.santuario:xmlsec
(Maven)
May 13, 2022
Improper Input Validation in Apache Santuario XML Security
Moderate
CVE-2013-4517
was published
for
org.apache.santuario:xmlsec
(Maven)
May 13, 2022
Bundler may install gems from a different source than expected
Moderate
CVE-2013-0334
was published
for
bundler
(RubyGems)
May 5, 2022
Jenkins Vulnerable to Denial of Service (DoS) via Crafted Payload
Moderate
CVE-2013-0331
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 5, 2022
Apache Tomcat Denial of Service via Malformed Request Headers
Moderate
CVE-2009-0033
was published
for
org.apache.tomcat:tomcat
(Maven)
May 2, 2022
OpenSymphony XWork vulnerable to improper input validation
Moderate
CVE-2007-4556
was published
for
opensymphony:xwork
(Maven)
May 1, 2022
Moodle does not properly validate module instance id
Moderate
CVE-2006-4936
was published
for
moodle/moodle
(Composer)
May 1, 2022
Improper Input Validation in Mortbay Jetty
Moderate
CVE-2006-2759
was published
for
org.mortbay.jetty:jetty
(Maven)
May 1, 2022
Typo3 Arbitrary File Delete
Moderate
CVE-2011-4902
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Typo3 Improper Access Control
Moderate
CVE-2011-4904
was published
for
typo3/cms
(Composer)
Apr 22, 2022
TYPO3 is vulnerable to Spam Abuse in the native form content element
Moderate
CVE-2010-3667
was published
for
typo3/cms-frontend
(Composer)
Apr 21, 2022
FormField with square brackets in field name skips validation
Moderate
CVE-2020-26138
was published
for
silverstripe/framework
(Composer)
Mar 26, 2022
Improper Input Validation in guzzlehttp/psr7
Moderate
CVE-2022-24775
was published
for
guzzlehttp/psr7
(Composer)
Mar 25, 2022
Spoofing attack in swagger-ui
Moderate
CVE-2018-25031
was published
for
org.webjars:swagger-ui
(Maven)
Mar 12, 2022
Improper Input Validation in url-js
Moderate
CVE-2022-25839
was published
for
url-js
(npm)
Mar 12, 2022
Improper Input Validation and Allocation of Resources Without Limits or Throttling in poi-scratchpad
Moderate
CVE-2022-26336
was published
for
org.apache.poi:poi-scratchpad
(Maven)
Mar 5, 2022
Leading white space bypasses protocol validation
Moderate
CVE-2022-24723
was published
for
urijs
(npm)
Mar 3, 2022
Crypt_GPG does not prevent additional options in GPG calls
Moderate
CVE-2022-24953
was published
for
pear/crypt_gpg
(Composer)
Feb 18, 2022
Directory traversal in Kubernetes Secrets Store CSI Driver
Moderate
CVE-2020-8568
was published
for
sigs.k8s.io/secrets-store-csi-driver
(Go)
Feb 15, 2022
Improper Input Validation in Docker Engine
Moderate
CVE-2020-13401
was published
for
github.com/docker/docker-ce
(Go)
Feb 15, 2022
ProTip!
Advisories are also available from the
GraphQL API