GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
460 advisories
Filter by severity
Kubernetes privilege escalation vulnerability
High
CVE-2023-3955
was published
for
k8s.io/kubernetes
(Go)
Oct 31, 2023
Ingress nginx annotation injection causes arbitrary command execution
High
CVE-2023-5043
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
High
CVE-2023-5044
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Ingress-nginx path sanitization can be bypassed
High
CVE-2022-4886
was published
for
k8s.io/ingress-nginx
(Go)
Oct 25, 2023
Apache Avro Java SDK vulnerable to Improper Input Validation
High
CVE-2023-39410
was published
for
org.apache.avro:avro
(Maven)
Sep 29, 2023
OpenCart Path Traversal vulnerability
High
CVE-2023-2315
was published
for
opencart/opencart
(Composer)
Sep 27, 2023
Denial of Service issue in quinn-proto
High
CVE-2023-42805
was published
for
quinn-proto
(Rust)
Sep 21, 2023
usememos/memos vulnerable to improper input validation
High
CVE-2023-4698
was published
for
github.com/usememos/memos
(Go)
Sep 1, 2023
Airflow Sqoop Provider RCE Vulnerability
High
CVE-2023-27604
was published
for
apache-airflow-providers-apache-sqoop
(pip)
Aug 28, 2023
Apache Airflow Spark Provider Improper Input Validation vulnerability
High
CVE-2023-40272
was published
for
apache-airflow-providers-apache-spark
(pip)
Aug 17, 2023
Woodpecker does not validate webhook before changing any data
High
CVE-2023-40034
was published
for
github.com/woodpecker-ci/woodpecker
(Go)
Aug 16, 2023
apache-airflow-providers-apache-drill Improper Input Validation vulnerability
High
CVE-2023-39553
was published
for
apache-airflow-providers-apache-drill
(pip)
Aug 11, 2023
lol-html panics on certain HTML inputs
High
CVE-2023-4241
was published
for
lol-html
(Rust)
Aug 9, 2023
import-in-the-middle has unsanitized user controlled input in module generation
High
CVE-2023-38704
was published
for
import-in-the-middle
(npm)
Aug 8, 2023
Denial of service in jackson-dataformats-text
High
CVE-2023-3894
was published
for
com.fasterxml.jackson.dataformat:jackson-dataformats-text
(Maven)
Aug 8, 2023
Possible image tampering from missing image validation for Packages
High
CVE-2023-38495
was published
for
github.com/crossplane/crossplane
(Go)
Jul 28, 2023
Apache Airflow Apache Hive Provider Improper Input Validation vulnerability
High
CVE-2023-37415
was published
for
apache-airflow-providers-apache-hive
(pip)
Jul 13, 2023
Apache Airflow Improper Input Validation vulnerability
High
CVE-2023-22888
was published
for
apache-airflow
(pip)
Jul 12, 2023
Apache Airflow Improper Input Validation vulnerability
High
CVE-2023-36543
was published
for
apache-airflow
(pip)
Jul 12, 2023
MechanicalSoup vulnerable to malicious web server reading arbitrary files on client using file input inside HTML form
High
CVE-2023-34457
was published
for
MechanicalSoup
(pip)
Jul 5, 2023
Apache Airflow JDBC Provider Improper Input Validation vulnerability
High
CVE-2023-22886
was published
for
apache-airflow-providers-jdbc
(pip)
Jun 29, 2023
Grav Server-side Template Injection (SSTI) via Twig Default Filters
High
CVE-2023-34448
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
avo possible unsafe reflection / partial DoS vulnerability
High
CVE-2023-34102
was published
for
avo
(RubyGems)
Jun 6, 2023
ProTip!
Advisories are also available from the
GraphQL API