GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
27,475 advisories
Filter by severity
Apache DolphinScheduler sensitive information disclosure
High
CVE-2023-48796
was published
for
apache-dolphinscheduler
(Maven)
Nov 24, 2023
openssl npm package vulnerable to command execution
Critical
CVE-2023-49210
was published
for
openssl
(npm)
Nov 23, 2023
Bouncy Castle Denial of Service (DoS)
Moderate
CVE-2023-33202
was published
for
org.bouncycastle:bcpkix-jdk18on
(Maven)
Nov 23, 2023
Apache Storm Local Information Disclosure Vulnerability in Storm-core on Unix-Like systems due temporary files
Moderate
CVE-2023-43123
was published
for
org.apache.storm:storm-core
(Maven)
Nov 23, 2023
Cross-site Scripting in DOMSanitizer
Moderate
CVE-2023-49146
was published
for
rhukster/dom-sanitizer
(Composer)
Nov 23, 2023
Cleartext Storage of Sensitive Information in HMAC SHA256 Authentication
Moderate
CVE-2023-48707
was published
for
codeigniter4/shield
(Composer)
Nov 23, 2023
Insertion of Sensitive Information into Log
Moderate
CVE-2023-48708
was published
for
codeigniter4/shield
(Composer)
Nov 23, 2023
Cross-site Scripting potential in custom links, job buttons, and computed fields
High
CVE-2023-48705
was published
for
nautobot
(pip)
Nov 22, 2023
Cross-site Scripting via uploaded assets
High
CVE-2023-48701
was published
for
statamic/cms
(Composer)
Nov 22, 2023
Directory Traversal in jeecg-boot
Moderate
CVE-2023-47467
was published
for
org.jeecgframework.boot:jeecg-boot-common
(Maven)
Nov 22, 2023
Cross Site Request Forgery in SwiftyEdit
High
CVE-2023-47350
was published
for
swiftyedit/swiftyedit
(Composer)
Nov 22, 2023
Cross-site Scripting in Admidio
Moderate
CVE-2023-47380
was published
for
admidio/admidio
(Composer)
Nov 22, 2023
SQL injection in Apache Submarine
Critical
CVE-2023-37924
was published
for
apache-submarine
(pip)
Nov 22, 2023
Elasticsearch Improper Handling of Exceptional Conditions
Moderate
CVE-2023-46673
was published
for
org.elasticsearch:elasticsearch
(Maven)
Nov 22, 2023
APM Java Agent Local Privilege Escalation issue
High
CVE-2021-37942
was published
for
co.elastic.apm:apm-agent-parent
(Maven)
Nov 22, 2023
Exposure of Sensitive Information in Elastic APM .NET Agent
Low
CVE-2021-22143
was published
for
Elastic.Apm
(NuGet)
Nov 22, 2023
Clear Text Credentials Exposed via Onboarding Task
Moderate
CVE-2023-48700
was published
for
nautobot-device-onboarding
(pip)
Nov 21, 2023
Download to arbitrary folder can lead to RCE
High
CVE-2023-47890
was published
for
pyload-ng
(pip)
Nov 21, 2023
Decryption of malicious PBES2 JWE objects can consume unbounded system resources
Moderate
GHSA-2c7c-3mj9-8fqh
was published
for
github.com/go-jose/go-jose/v3
(Go)
Nov 21, 2023
Possible user mocking that bypasses basic authentication
Moderate
CVE-2023-48309
was published
for
next-auth
(npm)
Nov 20, 2023
Bypass of field access control in strapi-plugin-protected-populate
Moderate
CVE-2023-48218
was published
for
strapi-plugin-protected-populate
(npm)
Nov 20, 2023
Cross-Site Request Forgery with QueryOnXWiki allows arbitrary database queries
High
CVE-2023-48293
was published
for
org.xwiki.contrib:xwiki-application-admintools
(Maven)
Nov 20, 2023
ProTip!
Advisories are also available from the
GraphQL API