GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,114
NuGet
735
pip
3,934
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,134 advisories
Filter by severity
Stored Cross-site Scripting in gitea
Moderate
CVE-2022-1928
was published
for
code.gitea.io/gitea
(Go)
May 30, 2022
Ignition config accessible to unprivileged software on VMware
Moderate
CVE-2022-1706
was published
for
github.com/coreos/ignition
(Go)
May 25, 2022
Pion/DLTS Accepts Client Certificates Without CertificateVerify
Moderate
CVE-2022-29222
was published
for
github.com/pion/dtls
(Go)
May 25, 2022
Pion/DTLS contains buffer for inbound DTLS fragments with no limit
Moderate
CVE-2022-29189
was published
for
github.com/pion/dtls
(Go)
May 24, 2022
Smokescreen SSRF via deny list bypass (square brackets)
Moderate
CVE-2022-29188
was published
for
github.com/stripe/smokescreen
(Go)
May 24, 2022
openark/orchestrator cross-site scripting vulnerability
Moderate
CVE-2021-27940
was published
for
github.com/openark/orchestrator
(Go)
May 24, 2022
InfluxDB Reflected Cross-site Scripting
Moderate
CVE-2018-17572
was published
for
github.com/influxdata/influxdb
(Go)
May 24, 2022
Incorrect Default Permissions in Beego
Moderate
CVE-2019-16355
was published
for
github.com/astaxie/beego
(Go)
May 24, 2022
DoS via malicious p2p message in Go Ethereum
Moderate
CVE-2022-29177
was published
for
github.com/ethereum/go-ethereum
(Go)
May 24, 2022
Cross-site Scripting in Gogs
Moderate
CVE-2022-1464
was published
for
gogs.io/gogs
(Go)
May 24, 2022
Istio Authorization Bypass Vulnerability
Moderate
CVE-2021-31920
was published
for
istio.io/istio
(Go)
May 24, 2022
•
withdrawn
golang.org/x/net/http/httpguts vulnerable to Uncontrolled Recursion
Moderate
CVE-2021-31525
was published
for
golang.org/x/net
(Go)
May 24, 2022
HashiCorp Consul Cross-site Scripting vulnerability
Moderate
CVE-2020-25864
was published
for
github.com/hashicorp/consul
(Go)
May 24, 2022
MongoDB Tools Improper Certificate Validation vulnerability
Moderate
CVE-2020-7924
was published
for
github.com/mongodb/mongo-tools
(Go)
May 24, 2022
Rancher Cross-site Scripting Vulnerability
Moderate
CVE-2021-25313
was published
for
github.com/rancher/rancher
(Go)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29245
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29244
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29243
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
Default inheritable capabilities for linux container should be empty
Moderate
CVE-2022-29162
was published
for
github.com/opencontainers/runc
(Go)
May 24, 2022
Heketi logs sensitive information
Moderate
CVE-2020-10763
was published
for
github.com/heketi/heketi
(Go)
May 24, 2022
Grafana XSS via a query alias for the ElasticSearch datasource
Moderate
CVE-2020-24303
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Gophish vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-24710
was published
for
github.com/gophish/gophish
(Go)
May 24, 2022
ingress-nginx component for Kubernetes allows file overwrite
Moderate
CVE-2020-8553
was published
for
k8s.io/ingress-nginx
(Go)
May 24, 2022
Grafana stored XSS
Moderate
CVE-2020-11110
was published
for
github.com/grafana/grafana
(Go)
May 24, 2022
Mattermost Server Sensitive Data Exposure
Moderate
CVE-2020-14457
was published
for
github.com/mattermost/mattermost-server/v5
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API