GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,493 advisories
Filter by severity
usememos/memos vulnerable to Improper Handling of Insufficient Permissions or Privileges
Moderate
CVE-2022-4863
was published
for
github.com/usememos/memos
(Go)
Dec 30, 2022
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4806
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Access Control vulnerability
High
CVE-2022-4809
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4804
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to stored Cross-site Scripting
Moderate
CVE-2022-4840
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos has Incorrectly Specified Destination in a Communication Channel
Moderate
CVE-2022-4847
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos Improper Access Control vulnerability
Moderate
CVE-2022-4807
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to Comparison of Object References Instead of Object Contents
Moderate
CVE-2022-4812
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to Cross-site Scripting
Critical
CVE-2022-4866
was published
for
github.com/usememos/memos
(Go)
Dec 31, 2022
shiyanhui/dht vulnerable to Uncontrolled Resource Consumption
High
CVE-2020-36562
was published
for
github.com/shiyanhui/dht
(Go)
Dec 28, 2022
usememos/memos Improper Access Control vulnerability
High
CVE-2022-4803
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos vulnerable to Improper Verification of Source of a Communication Channel
Moderate
CVE-2022-4848
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
usememos/memos Incorrect Use of Privileged APIs vulnerability
Moderate
CVE-2022-4805
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
nosurf vulnerable to improper input validation
High
CVE-2020-36564
was published
for
github.com/justinas/nosurf
(Go)
Dec 28, 2022
usememos/memos vulnerable to stored Cross-site Scripting
Moderate
CVE-2022-4839
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
pastebinit Path Traversal vulnerability
Moderate
CVE-2018-25059
was published
for
github.com/jessfraz/pastebinit
(Go)
Dec 30, 2022
usememos/memos Denial of Service vulnerability
High
CVE-2022-4767
was published
for
github.com/usememos/memos
(Go)
Dec 27, 2022
usememos/memos Improper Authorization vulnerability
Moderate
CVE-2022-4798
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
sememos/memos vulnerable to Improper Handling of Values
Moderate
CVE-2022-4851
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
gorilla/handlers may allow requester to bypass expected behavior of the Same Origin Policy
Critical
CVE-2017-20146
was published
for
github.com/gorilla/handlers
(Go)
Dec 28, 2022
usememos/memos Improper Authentication vulnerability
Moderate
CVE-2022-4799
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
usememos/memos has Insufficient Granularity of Access Control
Moderate
CVE-2022-4813
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
High
CVE-2020-36567
was published
for
github.com/gin-gonic/gin
(Go)
Dec 27, 2022
usememos/memos Cross-site Scripting vulnerability
Critical
CVE-2022-4865
was published
for
github.com/usememos/memos
(Go)
Dec 31, 2022
usememos/memos has Insufficient Granularity of Access Control
Moderate
CVE-2022-4801
was published
for
github.com/usememos/memos
(Go)
Dec 28, 2022
ProTip!
Advisories are also available from the
GraphQL API