GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
137,190 advisories
Filter by severity
VladTheEnterprising allows local users to write to arbitrary files via a symlink attack
Moderate
CVE-2014-4996
was published
for
VladTheEnterprising
(RubyGems)
May 14, 2022
Ember.js Cross-site Scripting vulnerability
Moderate
CVE-2014-0013
was published
for
ember-source
(RubyGems)
May 14, 2022
katello Improper Privilege Management vulnerability
Moderate
CVE-2017-2662
was published
for
katello
(RubyGems)
May 13, 2022
Initial debug-host handler implementation could leak information and facilitate denial of service
Moderate
GHSA-x477-fq37-q5wr
was published
for
fortio.org/proxy
(Go)
Jan 27, 2023
Cross-site request forgery vulnerability in Jenkins JIRA Pipeline Steps Plugin
Moderate
CVE-2023-24437
was published
for
org.jenkins-ci.plugins:jira-steps
(Maven)
Jan 26, 2023
There is an information leakage vulnerability in FusionCompute 6.5.1, eCNS280_TD V100R005C00 and...
Moderate
Unreviewed
CVE-2021-37036
was published
Nov 24, 2021
Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java
Moderate
CVE-2022-21363
was published
for
mysql:mysql-connector-java
(Maven)
Jan 20, 2022
Async-h1 request smuggling possible with long unread bodies
Moderate
CVE-2020-26281
was published
for
async-h1
(Rust)
Oct 12, 2021
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior,...
Moderate
Unreviewed
CVE-2021-20862
was published
Dec 2, 2021
Cross-site Scripting in moodle
Moderate
CVE-2021-43558
was published
for
moodle/moodle
(Composer)
Nov 23, 2021
IBM QRadar SIEM 7.3 and 7.4 could allow an attacker to obtain sensitive information due to the...
Moderate
Unreviewed
CVE-2021-29779
was published
Dec 2, 2021
CSRF vulnerability in Jenkins SWAMP Plugin allows capturing credentials
Moderate
CVE-2022-25212
was published
for
org.continuousassurance.swamp.jenkins:swamp
(Maven)
Feb 16, 2022
Missing permission check in Jenkins SWAMP Plugin allows capturing credentials
Moderate
CVE-2022-25211
was published
for
org.continuousassurance.swamp.jenkins:swamp
(Maven)
Feb 16, 2022
Foxit PDF Reader and Editor before 11.2.1 and PhantomPDF before 10.1.7 allow a NULL pointer...
Moderate
Unreviewed
CVE-2022-25108
was published
Mar 11, 2022
Vault Enterprise clusters using the tokenization transform feature can expose the tokenization...
Moderate
Unreviewed
CVE-2022-25244
was published
Mar 11, 2022
Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote...
Moderate
Unreviewed
CVE-2022-25215
was published
Mar 11, 2022
Luocms v2.0 is affected by Cross Site Scripting (XSS) in /admin/news/sort_add.php and /inc...
Moderate
Unreviewed
CVE-2022-24608
was published
Mar 11, 2022
Fiori launchpad - versions 754, 755, 756, does not sufficiently encode user-controlled inputs,...
Moderate
Unreviewed
CVE-2022-26101
was published
Mar 11, 2022
Directory traversal vulnerability in pfSense-pkg-WireGuard pfSense-pkg-WireGuard 0.1.5 versions...
Moderate
Unreviewed
CVE-2022-21132
was published
Mar 11, 2022
Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9...
Moderate
Unreviewed
CVE-2022-21170
was published
Mar 11, 2022
The SAP Focused Run (Real User Monitoring) - versions 200, 300, REST service does not...
Moderate
Unreviewed
CVE-2022-24399
was published
Mar 11, 2022
Persistent cross-site scripting in the web interface of ipDIO allows an unauthenticated remote...
Moderate
Unreviewed
CVE-2022-21146
was published
Mar 11, 2022
A stack overflow bug in the document extractor in Mattermost Server in versions up to and...
Moderate
Unreviewed
CVE-2022-0904
was published
Mar 11, 2022
Persistent cross-site scripting (XSS) in the web interface of ipDIO allows an authenticated...
Moderate
Unreviewed
CVE-2022-24432
was published
Mar 11, 2022
A cross-site scripting (XSS) vulnerability in the component cgi-bin/ej.cgi of Ex libris ALEPH 500...
Moderate
Unreviewed
CVE-2022-24177
was published
Mar 11, 2022
ProTip!
Advisories are also available from the
GraphQL API