GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,134 advisories
Filter by severity
Answer vulnerable to Exposure of Sensitive Information Through Metadata
Moderate
CVE-2023-1974
was published
for
github.com/answerdev/answer
(Go)
Apr 11, 2023
Docker Swarm encrypted overlay network with a single endpoint is unauthenticated
Moderate
CVE-2023-28842
was published
for
github.com/docker/docker
(Go)
Apr 4, 2023
Docker Swarm encrypted overlay network traffic may be unencrypted
Moderate
CVE-2023-28841
was published
for
github.com/docker/docker
(Go)
Apr 4, 2023
Symlink following allows leaking out-of-bound manifests and JSON files from Argo CD repo-server
Moderate
CVE-2022-24904
was published
for
github.com/argoproj/argo-cd/v2
(Go)
May 23, 2022
Mattermost fails to properly authentication inviter's permissions to private channel
Moderate
CVE-2023-1774
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 31, 2023
OpenFGA Authorization Bypass
Moderate
CVE-2022-39352
was published
for
github.com/openfga/openfga
(Go)
Nov 8, 2022
Uncontrolled Resource Consumption in github.com/google/fscrypt
Moderate
CVE-2022-25326
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
Phachon mm-wiki vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2020-19277
was published
for
github.com/phachon/mm-wiki
(Go)
Apr 4, 2023
Improper Access Control in github.com/treeverse/lakefs
Moderate
GHSA-m836-gxwq-j2pm
was published
for
github.com/treeverse/lakefs
(Go)
Oct 28, 2021
Mattermost vulnerable to information disclosure
Moderate
CVE-2023-1775
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 31, 2023
Mattermost vulnerable to cross-site scripting (XSS)
Moderate
CVE-2023-1776
was published
for
github.com/mattermost/mattermost-server
(Go)
Mar 31, 2023
studygolang vulnerable to cross-site scripting
Moderate
CVE-2021-4272
was published
for
github.com/studygolang/studygolang
(Go)
Dec 21, 2022
fieldpath's Paved.SetValue allows growing arrays up to arbitrary sizes in crossplane-runtime
Moderate
CVE-2023-27483
was published
for
github.com/crossplane/crossplane-runtime
(Go)
Mar 13, 2023
Argo CD authenticated but unauthorized users may enumerate Application names via the API
Moderate
CVE-2022-41354
was published
for
github.com/argoproj/argo-cd
(Go)
Mar 23, 2023
OpenShift Assisted Installer leaks image pull secrets as plaintext in installation logs
Moderate
CVE-2021-3684
was published
for
github.com/openshift/assisted-installer
(Go)
Mar 24, 2023
Answer has Guessable CAPTCHA
Moderate
CVE-2023-1539
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Cross-site Scripting in Mattermost
Moderate
CVE-2021-37860
was published
for
github.com/mattermost/mattermost-server/v5
(Go)
Sep 23, 2021
Duplicate Advisory: KubeVirt arbitrary host file read from the VM
Moderate
CVE-2022-1798
was published
for
kubevirt.io/kubevirt
(Go)
Aug 18, 2022
•
withdrawn
imgproxy Cross-site Scripting vulnerability
Moderate
CVE-2023-1496
was published
for
github.com/imgproxy/imgproxy/v3
(Go)
Mar 19, 2023
User login denial of service in github.com/google/fscrypt
Moderate
CVE-2022-25327
was published
for
github.com/google/fscrypt
(Go)
Feb 26, 2022
Velociraptor subject to Path Traversal
Moderate
CVE-2023-0290
was published
for
www.velocidex.com/golang/velociraptor
(Go)
Jan 19, 2023
usememos/memos Cross-Site Request Forgery vulnerability
Moderate
CVE-2022-4849
was published
for
github.com/usememos/memos
(Go)
Dec 29, 2022
Cross-site Scripting in github.com/schollz/rwtxt
Moderate
CVE-2021-20848
was published
for
github.com/schollz/rwtxt
(Go)
Nov 29, 2021
Gophish vulnerable to Cross-site Scripting via crafted landing page
Moderate
CVE-2022-45004
was published
for
github.com/gophish/gophish
(Go)
Mar 22, 2023
Default inheritable capabilities for linux container should be empty
Moderate
CVE-2022-29162
was published
for
github.com/opencontainers/runc
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API