GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,683
Erlang
29
GitHub Actions
16
Go
1,708
Maven
4,944
npm
3,473
NuGet
603
pip
2,995
Pub
10
RubyGems
826
Rust
773
Swift
34
Unreviewed advisories
All unreviewed
5,000+
8,371 advisories
Filter by severity
json-path Out-of-bounds Write vulnerability
Moderate
CVE-2023-51074
was published
for
com.jayway.jsonpath:json-path
(Maven)
Dec 27, 2023
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address
Moderate
CVE-2024-35175
was published
for
github.com/tg123/sshpiper
(Go)
May 14, 2024
Improper escaping in Apache Zeppelin
Moderate
CVE-2024-31866
was published
for
org.apache.zeppelin:zeppelin-interpreter
(Maven)
Apr 9, 2024
Drupal core Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2020-13672
was published
for
drupal/core
(Composer)
Feb 12, 2022
XML External Entity (XXE) in Django
Moderate
CVE-2013-1665
was published
for
Django
(pip)
May 17, 2022
Kwik does not discard unused encryption keys
Moderate
CVE-2024-22588
was published
for
tech.kwik:kwik
(Maven)
May 24, 2024
Jenkins Report Info Plugin Path Traversal vulnerability
Moderate
CVE-2024-5273
was published
for
org.jenkins-ci.plugins:report-info
(Maven)
May 24, 2024
PHP Server Monitor vulnerable to Cross-site Scripting
Moderate
CVE-2024-5312
was published
for
phpservermon/phpservermon
(Composer)
May 24, 2024
OpenStack Identity (Keystone) Denial of Service
Moderate
CVE-2013-2014
was published
for
keystone
(pip)
May 13, 2022
MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2007-0857
was published
for
moin
(pip)
May 1, 2022
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
Moderate
CVE-2024-32077
was published
for
apache-airflow
(pip)
May 14, 2024
OpenStack Glance Server-Side Request Forgery (SSRF)
Moderate
CVE-2017-7200
was published
for
glance
(pip)
May 17, 2022
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting
Moderate
CVE-2024-34081
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
Bouncy Castle Denial of Service (DoS)
Moderate
CVE-2023-33202
was published
for
org.bouncycastle:bcpkix-jdk18on
(Maven)
Nov 23, 2023
silverstripe/framework ReadOnly transformation for formfields exploitable
Moderate
GHSA-97jm-g33h-f46g
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter
Moderate
GHSA-mpqj-f4v3-334h
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing CSRF protection in login form
Moderate
GHSA-vj2j-6g3w-4662
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe XSS in CMS Edit Page
Moderate
GHSA-m8v7-x398-pxrf
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers
Moderate
GHSA-87pf-7x99-5xc4
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter
Moderate
GHSA-2hpc-mf4q-j885
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Missing security check on dev/build/defaults
Moderate
GHSA-x5w2-wcr8-9q45
was published
for
silverstripe/framework
(Composer)
May 23, 2024
ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool`
Moderate
GHSA-2557-x9mg-76w8
was published
for
github.com/cosmos/cosmos-sdk
(Go)
Feb 21, 2024
Silverstripe HtmlEditor embed url sanitisation
Moderate
GHSA-qp29-wcc2-vmpc
was published
for
silverstripe/framework
(Composer)
May 23, 2024
Silverstripe Form field validation message XSS vulnerability
Moderate
GHSA-j982-5jv7-v43r
was published
for
silverstripe/framework
(Composer)
May 23, 2024
ProTip!
Advisories are also available from the
GraphQL API