GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,678
Erlang
29
GitHub Actions
16
Go
1,707
Maven
4,940
npm
3,471
NuGet
603
pip
2,993
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
107,408 advisories
Filter by severity
In Tiny File Manager 2.4.1, there is a vulnerability in the ajax file backup copy functionality...
Moderate
Unreviewed
CVE-2020-12103
was published
May 24, 2022
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive...
Moderate
Unreviewed
CVE-2020-12102
was published
May 24, 2022
OpenStack Identity (Keystone) Denial of Service
Moderate
CVE-2013-2014
was published
for
keystone
(pip)
May 13, 2022
MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2007-0857
was published
for
moin
(pip)
May 1, 2022
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
Moderate
CVE-2024-32077
was published
for
apache-airflow
(pip)
May 14, 2024
OpenStack Glance Server-Side Request Forgery (SSRF)
Moderate
CVE-2017-7200
was published
for
glance
(pip)
May 17, 2022
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
Moderate
CVE-2024-34081
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
yasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at ...
Moderate
Unreviewed
CVE-2023-29582
was published
Apr 24, 2023
Bouncy Castle Denial of Service (DoS)
Moderate
CVE-2023-33202
was published
for
org.bouncycastle:bcpkix-jdk18on
(Maven)
Nov 23, 2023
silverstripe/framework ReadOnly transformation for formfields exploitable
Moderate
GHSA-97jm-g33h-f46g
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter
Moderate
GHSA-mpqj-f4v3-334h
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing CSRF protection in login form
Moderate
GHSA-vj2j-6g3w-4662
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in CMS Edit Page
Moderate
GHSA-m8v7-x398-pxrf
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers
Moderate
GHSA-87pf-7x99-5xc4
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter
Moderate
GHSA-2hpc-mf4q-j885
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing security check on dev/build/defaults
Moderate
GHSA-x5w2-wcr8-9q45
was published
for
silverstripe/framework
(Composer)
May 23, 2024
ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool`
Moderate
GHSA-2557-x9mg-76w8
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 21, 2024
The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2024-4365
was published
May 23, 2024
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5e: Fix null deref...
Moderate
Unreviewed
CVE-2021-47164
was published
Mar 25, 2024
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP...
Moderate
Unreviewed
CVE-2018-5729
was published
May 13, 2022
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP...
Moderate
Unreviewed
CVE-2018-5730
was published
May 13, 2022
Silverstripe HtmlEditor embed url sanitisation
Moderate
GHSA-qp29-wcc2-vmpc
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Form field validation message XSS vulnerability
Moderate
GHSA-j982-5jv7-v43r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php
Moderate
GHSA-mqf5-275h-gf6r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation
Moderate
GHSA-g4hp-pfvf-vm5w
was published
for
silverstripe/framework
(Composer)
May 23, 2024
ProTip!
Advisories are also available from the
GraphQL API