GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
11,252 advisories
Filter by severity
CosmWasm affected by arithmetic overflows
Low
GHSA-8724-5xmm-w5xq
was published
for
cosmwasm-std
(Rust)
Apr 24, 2024
Caddy allows enumeration of Certificates and Hostnames
Low
CVE-2018-19148
was published
for
github.com/caddyserver/caddy
(Go)
May 14, 2022
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a...
Low
Unreviewed
CVE-2024-4141
was published
Apr 24, 2024
EC-CUBE Directory traversal vulnerability
Low
CVE-2022-40199
was published
for
ec-cube/ec-cube
(Composer)
Sep 28, 2022
TYPO3 cross-site scripting (XSS)
Low
CVE-2015-5956
was published
for
typo3/cms
(Composer)
May 14, 2022
A vulnerability, which was classified as problematic, has been found in NetBox up to 3.7.0. This...
Low
Unreviewed
CVE-2024-0948
was published
Jan 27, 2024
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security:...
Low
Unreviewed
CVE-2024-21000
was published
Apr 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE ...
Low
Unreviewed
CVE-2024-21003
was published
Apr 17, 2024
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition...
Low
Unreviewed
CVE-2024-21068
was published
Apr 17, 2024
A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This...
Low
Unreviewed
CVE-2024-4235
was published
Apr 26, 2024
Mattermost allows team admins to promote guests to team admins
Low
CVE-2024-4195
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost fails to fully validate role changes
Low
CVE-2024-4198
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
Mattermost fails to limit the size of a request path
Low
CVE-2024-22091
was published
for
github.com/mattermost/mattermost-server
(Go)
Apr 26, 2024
The BackUpWordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up...
Low
Unreviewed
CVE-2024-3034
was published
Apr 27, 2024
A vulnerability was found in Techkshetra Info Solutions Savsoft Quiz 6.0 and classified as...
Low
Unreviewed
CVE-2024-4256
was published
Apr 27, 2024
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Low
CVE-2024-30261
was published
for
undici
(npm)
Apr 4, 2024
A vulnerability was found in Juanpao JPShop up to 1.5.02. It has been declared as problematic....
Low
Unreviewed
CVE-2024-1258
was published
Feb 6, 2024
In the Linux kernel, the following vulnerability has been resolved:
drm/buddy: Fix alloc_range()...
Low
Unreviewed
CVE-2024-26911
was published
Apr 17, 2024
A flaw was found in the mod_proxy_cluster in the Apache server. This issue may allow a malicious...
Low
Unreviewed
CVE-2023-6710
was published
Dec 13, 2023
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a local user to obtain or modify sensitive...
Low
Unreviewed
CVE-2023-37397
was published
Apr 19, 2024
XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets
Low
CVE-2024-31573
was published
for
org.xmlunit:xmlunit-core
(Maven)
May 1, 2024
Undici proxy-authorization header not cleared on cross-origin redirect in fetch
Low
CVE-2024-24758
was published
for
undici
(npm)
Feb 16, 2024
An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on...
Low
Unreviewed
CVE-2024-23462
was published
May 2, 2024
Wagtail has permission check bypass when editing a model with per-field restrictions through `wagtail.contrib.settings` or `ModelViewSet`
Low
CVE-2024-32882
was published
for
wagtail
(pip)
May 1, 2024
Kofax Power PDF JPG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This...
Low
Unreviewed
CVE-2023-37352
was published
May 3, 2024
ProTip!
Advisories are also available from the
GraphQL API