GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,134 advisories
Filter by severity
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Moderate
CVE-2023-22462
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
teler-waf contains detection rule bypass via Entities payload
Moderate
CVE-2023-26047
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
teler-waf subject to Bypass of Common Web Attack Threat Rule with HTML Entities Payload
Moderate
CVE-2023-26046
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
Juju controller - Arbitrary file reading vulnerability
Moderate
CVE-2023-0092
was published
for
github.com/juju/juju
(Go)
Mar 1, 2023
Grafana vulnerable to Cross-site Scripting
Moderate
CVE-2023-0507
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
Grafana vulnerable to Cross-site Scripting
Moderate
CVE-2023-0594
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-0934
was published
for
github.com/answerdev/answer
(Go)
Feb 21, 2023
Uncontrolled Resource Consumption in golang.org/x/image
Moderate
CVE-2022-41727
was published
for
golang.org/x/image
(Go)
Feb 17, 2023
Uncontrolled Resource Consumption in Hashicorp Nomad
Moderate
CVE-2023-0821
was published
for
github.com/hashicorp/nomad
(Go)
Feb 17, 2023
Data Amplification in HashiCorp go-getter
Moderate
CVE-2023-0475
was published
for
github.com/hashicorp/go-getter
(Go)
Feb 16, 2023
OCI image importer memory exhaustion in github.com/containerd/containerd
Moderate
CVE-2023-25153
was published
for
github.com/containerd/containerd
(Go)
Feb 16, 2023
Supplementary groups are not set up properly in github.com/containerd/containerd
Moderate
CVE-2023-25173
was published
for
github.com/containerd/containerd
(Go)
Feb 16, 2023
Cross Site Scripting in usememos/memos
Moderate
CVE-2022-25978
was published
for
github.com/usememos/memos
(Go)
Feb 15, 2023
Denial of service via HAMT Decoding Panics
Moderate
CVE-2023-23625
was published
for
github.com/ipfs/go-unixfs
(Go)
Feb 10, 2023
IPFS go-bitfield vulnerable to DoS via malformed size arguments
Moderate
CVE-2023-23626
was published
for
github.com/ipfs/go-bitfield
(Go)
Feb 10, 2023
Argo CD leaks repository credentials in user-facing error messages and in logs
Moderate
CVE-2023-25163
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Feb 8, 2023
Helm vulnerable to information disclosure via getHostByName Function
Moderate
CVE-2023-25165
was published
for
helm.sh/helm/v3
(Go)
Feb 8, 2023
Credential disclosure in syft when SYFT_ATTEST_PASSWORD environment variable set
Moderate
CVE-2023-24827
was published
for
github.com/anchore/syft
(Go)
Feb 8, 2023
Answer vulnerable to Race Condition
Moderate
CVE-2023-0739
was published
for
github.com/answerdev/answer
(Go)
Feb 8, 2023
Denial of Service in dhowden/tag
Moderate
CVE-2020-29242
was published
for
github.com/dhowden/tag
(Go)
Feb 7, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2
Moderate
GHSA-4xgv-j62q-h3rj
was published
for
github.com/pion/dtls
(Go)
Feb 7, 2023
Panic during unmarshal of Hello Verify Request in github.com/pion/dtls/v2
Moderate
GHSA-hxp2-xqf3-v83h
was published
for
github.com/pion/dtls
(Go)
Feb 7, 2023
Open Redirect in Caddy
Moderate
CVE-2022-28923
was published
for
github.com/caddyserver/caddy/v2
(Go)
Feb 7, 2023
Openshift Enterprise source-to-image vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip)
Moderate
CVE-2018-1103
was published
for
github.com/openshift/source-to-image
(Go)
Feb 6, 2023
Kubernetes client-go vulnerable to Sensitive Information Leak via Log File
Moderate
CVE-2020-8565
was published
for
k8s.io/client-go
(Go)
Feb 6, 2023
ProTip!
Advisories are also available from the
GraphQL API