GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
8,371 advisories
Filter by severity
Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"
Moderate
GHSA-qm5v-pj64-852j
was published
for
passbolt/passbolt_api
(Composer)
May 20, 2024
Passbolt Api E-mail HTML injection
Moderate
GHSA-v86m-j5f7-ccwh
was published
for
passbolt/passbolt_api
(Composer)
May 20, 2024
aiosmtpd STARTTLS unencrypted commands injection
Moderate
CVE-2024-34083
was published
for
aiosmtpd
(pip)
May 20, 2024
OroPlatform Forced Redirect to External Website
Moderate
GHSA-3vhm-q4w3-rw8q
was published
for
oro/platform
(Composer)
May 20, 2024
OroCRM Forced Redirect to External Website
Moderate
GHSA-v8hp-239v-9367
was published
for
oro/crm
(Composer)
May 20, 2024
Tor path lengths too short when "full Vanguards" configured
Moderate
CVE-2024-35313
was published
for
arti
(Rust)
May 18, 2024
onelogin/php-saml signature wrapping attacks
Moderate
CVE-2016-1000253
was published
for
onelogin/php-saml
(Composer)
May 17, 2024
Privilege Escalation in TYPO3 Neos
Moderate
GHSA-43cf-7f3h-38rg
was published
for
neos/neos
(Composer)
May 17, 2024
Time-Based Information Disclosure Vulnerability in Flow
Moderate
GHSA-6pq8-67pw-j6hw
was published
for
neos/flow
(Composer)
May 17, 2024
Neos Flow Information disclosure in entity security
Moderate
GHSA-9cw3-j7wg-jwj8
was published
for
neos/flow
(Composer)
May 17, 2024
Neos Flow Arbitrary file upload and XML External Entity processing
Moderate
GHSA-5vv7-j593-mgjc
was published
for
neos/flow
(Composer)
May 17, 2024
Submariner Operator sets unnecessary RBAC permissions in helm charts
Moderate
CVE-2024-5042
was published
for
github.com/submariner-io/submariner-operator
(Go)
May 17, 2024
Denial of service of Minder Server with attacker-controlled REST endpoint
Moderate
CVE-2024-35185
was published
for
github.com/stacklok/minder
(Go)
May 16, 2024
REXML contains a denial of service vulnerability
Moderate
CVE-2024-35176
was published
for
rexml
(RubyGems)
May 16, 2024
MLflow allows low privilege users to delete any artifact
Moderate
CVE-2024-4263
was published
for
mlflow
(pip)
May 16, 2024
Magento Cross-Site Scripting (XSS) vulnerability
Moderate
GHSA-mcfc-67vm-j568
was published
for
magento/community-edition
(Composer)
May 15, 2024
Data Leakage Vulnerability in livewire/livewire
Moderate
GHSA-qwvp-268g-jjm8
was published
for
livewire/livewire
(Composer)
May 15, 2024
Insecure State Generation in laravel/socialite
Moderate
GHSA-h97c-qp24-439v
was published
for
laravel/socialite
(Composer)
May 15, 2024
State Guessing Vulnerability in laravel/socialite
Moderate
GHSA-7fjv-25q9-2w88
was published
for
laravel/socialite
(Composer)
May 15, 2024
Laravel Guard bypass in Eloquent models
Moderate
GHSA-44pg-c29v-hp6r
was published
for
laravel/framework
(Composer)
May 15, 2024
Laravel Cross-site Scripting (XSS) vulnerability in blade templating
Moderate
GHSA-vr95-p7q6-8m9q
was published
for
laravel/framework
(Composer)
May 15, 2024
Laravel Encrypter Component Potential Decryption Failure Leading to Unintended Behavior
Moderate
GHSA-7852-w36x-6mf6
was published
for
laravel/framework
(Composer)
May 15, 2024
Laravel Hijacked authentication cookies vulnerability
Moderate
GHSA-p62r-7637-3wwc
was published
for
laravel/framework
(Composer)
May 15, 2024
Laravel Risk of mass-assignment vulnerabilities
Moderate
GHSA-rj3w-99gc-8j58
was published
for
laravel/framework
(Composer)
May 15, 2024
Read private customer data reclaiming carts in Klaviyo Magento
Moderate
GHSA-hvgw-gg3p-295j
was published
for
klaviyo/magento2-extension
(Composer)
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API