GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,615 advisories
Filter by severity
Winter CMS stored XSS through privileged upload of SVG file
Low
CVE-2023-37269
was published
for
wintercms/winter
(Composer)
Jul 7, 2023
Stylelint has vulnerability in semver dependency
Low
GHSA-f7xj-rg7h-mc87
was published
for
stylelint
(npm)
Jul 7, 2023
•
withdrawn
Pipelines do not validate child UIDs
Low
CVE-2023-37264
was published
for
github.com/tektoncd/pipeline
(Go)
Jul 7, 2023
Graylog server has partial path traversal vulnerability in Support Bundle feature
Low
CVE-2023-41044
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Graylog vulnerable to insecure source port usage for DNS queries
Low
CVE-2023-41045
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Graylog user session is still usable after logout
Low
CVE-2023-41041
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
Magento Open Source allows Cross-Site Scripting (XSS)
Low
CVE-2023-22249
was published
for
magento/community-edition
(Composer)
Jul 6, 2023
code.gitea.io/gitea Open Redirect vulnerability
Low
CVE-2023-3515
was published
for
code.gitea.io/gitea
(Go)
Jul 5, 2023
github.com/cosmos/cosmos-sdk's x/crisis does not charge ConstantFee
Low
GHSA-w5w5-2882-47pc
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Jun 30, 2023
Client Spoofing within the Keycloak Device Authorisation Grant
Low
CVE-2023-2585
was published
for
org.keycloak:keycloak-server-spi-private
(Maven)
Jun 30, 2023
Temporal Server vulnerable to Incorrect Authorization and Insecure Default Initialization of Resource
Low
CVE-2023-3485
was published
for
go.temporal.io/server
(Go)
Jun 30, 2023
SafeURL-Python's hostname blocklist does not block FQDNs
Low
GHSA-373w-rj84-pv6x
was published
for
SafeURL-Python
(pip)
Jun 29, 2023
SpiceDB's LookupResources may return partial results
Low
CVE-2023-35930
was published
for
github.com/authzed/spicedb
(Go)
Jun 28, 2023
Spina Cross-site Scripting vulnerability
Low
CVE-2023-3445
was published
for
spina
(RubyGems)
Jun 28, 2023
Admidio Improper Access Control vulnerability
Low
CVE-2023-3303
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
Shescape potential environment variable exposure on Windows with CMD
Low
CVE-2023-35931
was published
for
shescape
(npm)
Jun 22, 2023
Vaadin vulnerable to possible information disclosure of class and method names in RPC response
Low
CVE-2023-25500
was published
for
com.vaadin:flow-server
(Maven)
Jun 22, 2023
@apollo/server vulnerable to unsafe application of Content Security Policy via reused nonces
Low
GHSA-68jh-rf6x-836f
was published
for
@apollo/server
(npm)
Jun 16, 2023
Cilium vulnerable to information leakage via incorrect ReferenceGrant handling
Low
CVE-2023-34242
was published
for
github.com/cilium/cilium
(Go)
Jun 16, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29295
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Low
CVE-2023-29296
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source affected by Improper Input Validation
Low
CVE-2023-29293
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source has Business Logic Errors Vulnerability
Low
CVE-2023-29294
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
fast-xml-parser regex vulnerability patch could be improved from a safety perspective
Low
GHSA-gpv5-7x3g-ghjv
was published
for
fast-xml-parser
(npm)
Jun 15, 2023
ProTip!
Advisories are also available from the
GraphQL API