GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,126
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,021
Swift
39
Unreviewed advisories
All unreviewed
5,000+
116 advisories
Filter by severity
The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or...
Moderate
Unreviewed
CVE-2022-22734
was published
Mar 15, 2022
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface...
Moderate
Unreviewed
CVE-2021-43106
was published
Feb 15, 2022
An issue was discovered in the Calendar feature in Zimbra Collaboration Suite 8.8.x before 8.8.15...
Moderate
Unreviewed
CVE-2022-24682
was published
Feb 10, 2022
Improper Output Neutralization and Improper Encoding or Escaping of Output for Logs in ansible
Moderate
CVE-2020-14330
was published
for
ansible
(pip)
Feb 9, 2022
Path traversal in xwiki-platform-skin-skinx
Moderate
CVE-2022-23620
was published
for
org.xwiki.platform:xwiki-platform-skin-skinx
(Maven)
Feb 9, 2022
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27,...
Moderate
Unreviewed
CVE-2022-0220
was published
Feb 2, 2022
An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user...
Moderate
Unreviewed
CVE-2021-45226
was published
Jan 25, 2022
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is...
Moderate
Unreviewed
CVE-2021-29872
was published
Jan 19, 2022
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to...
Moderate
Unreviewed
CVE-2022-0210
was published
Jan 19, 2022
There is an information leak vulnerability in eCNS280_TD V100R005C10SPC650. The vulnerability is...
Moderate
Unreviewed
CVE-2021-40007
was published
Dec 14, 2021
Apache Airavata Django Portal allows CRLF log injection because of lack of escaping log...
Moderate
Unreviewed
CVE-2021-43410
was published
Dec 10, 2021
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI...
Moderate
Unreviewed
CVE-2021-20844
was published
Nov 25, 2021
Authentication Bypass by Alternate Name in Apache Tomcat
Moderate
CVE-2021-30640
was published
for
org.apache.tomcat:tomcat
(Maven)
Aug 13, 2021
Misinterpretation of malicious XML input
Moderate
CVE-2021-32796
was published
for
@xmldom/xmldom
(npm)
Aug 3, 2021
Control character injection in console output in github.com/ipfs/go-ipfs
Moderate
CVE-2020-26283
was published
for
github.com/ipfs/go-ipfs
(Go)
Jun 23, 2021
Insert tag injection in the Contao login module
Moderate
CVE-2019-19714
was published
for
contao/contao
(Composer)
Dec 17, 2019
ProTip!
Advisories are also available from the
GraphQL API