GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,160 advisories
Filter by severity
Improper Input Validation in OpenCV
Moderate
CVE-2016-1517
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
Out-of-bounds Write in OpenCV
Moderate
CVE-2017-14136
was published
for
opencv-contrib-python
(pip)
Oct 12, 2021
Denial of service in DataCommunicator class in Vaadin 8
Moderate
GHSA-j23j-q57m-63v3
was published
for
com.vaadin:vaadin-server
(Maven)
Oct 13, 2021
Open Redirect in OAuth2 Proxy
Moderate
CVE-2020-4037
was published
for
github.com/oauth2-proxy/oauth2-proxy
(Go)
Dec 20, 2021
Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript
Moderate
GHSA-h45p-w933-jxh3
was published
for
@aws-crypto/client-browser
(npm)
Jun 1, 2021
Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19
Moderate
GHSA-fr26-qjc8-mvjx
was published
for
com.vaadin:flow-server
(Maven)
Oct 13, 2021
Unexpected panics in num-bigint
Moderate
GHSA-v935-pqmr-g8v9
was published
for
num-bigint
(Rust)
Nov 3, 2021
ReDoS in LDAP schema parser
Moderate
GHSA-r8wq-qrxc-hmcm
was published
for
python-ldap
(pip)
Nov 29, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
Unchecked hostname resolution could allow access to local network resources by users outside the local network
Moderate
GHSA-6rg3-8h8x-5xfv
was published
for
github.com/pterodactyl/wings
(Go)
Jun 23, 2021
Arbitrary Command Injection due to Improper Command Sanitization
Moderate
GHSA-hxwm-x553-x359
was published
for
@npmcli/git
(npm)
Aug 5, 2021
VecStorage Deserialize Allows Violation of Length Invariant
Moderate
GHSA-h3mf-4fwp-59c7
was published
for
nalgebra
(Rust)
Aug 5, 2021
•
withdrawn
Queue<T> should have a Send bound on its Send/Sync traits
Moderate
GHSA-v42f-j8fx-99f3
was published
for
scottqueue
(Rust)
Aug 25, 2021
•
withdrawn
XSS in richtext custom tag attributes in ezsystems/ezplatform-richtext
Moderate
GHSA-9jp8-cwwx-p64q
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Dec 1, 2021
Regular Expression Denial of Service in millisecond
Moderate
GHSA-m489-xr35-fjxr
was published
for
millisecond
(npm)
Sep 22, 2021
Vulnerable dependency in XTDB connector
Moderate
GHSA-hwvm-vfw8-93mw
was published
for
org.odpi.egeria:egeria-connector-xtdb
(Maven)
Dec 16, 2021
Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
Moderate
GHSA-755v-r4x4-qf7m
was published
for
org.keycloak:keycloak-core
(Maven)
Nov 29, 2022
Apiman Manager API affected by Jackson denial of service vulnerability
Moderate
GHSA-q95j-488q-5q3p
was published
for
io.apiman:apiman-manager-api-impl
(Maven)
Jan 9, 2023
TYPO3 HTML Sanitizer Bypasses Cross-Site Scripting Protection
Moderate
GHSA-gqqf-g5r7-84vf
was published
for
typo3/cms-core
(Composer)
Sep 15, 2022
XSS vulnerability in translations
Moderate
GHSA-rrgw-3hg3-9x8c
was published
for
oro/platform
(Composer)
Jan 12, 2022
Book page text, count, and author/title length is not limited in PocketMine-MP
Moderate
GHSA-p62j-hrxm-xcxf
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 6, 2022
GovernorCompatibilityBravo incorrect ABI encoding may lead to unexpected behavior
Moderate
GHSA-m6w8-fq7v-ph4m
was published
for
@openzeppelin/contracts
(npm)
Jan 13, 2022
ProTip!
Advisories are also available from the
GraphQL API