Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8,371 advisories

json-path Out-of-bounds Write vulnerability Moderate
CVE-2023-51074 was published for com.jayway.jsonpath:json-path (Maven) Dec 27, 2023
phrabec SunBK201
sshpiper's enabling of proxy protocol without proper feature flagging allows faking source address Moderate
CVE-2024-35175 was published for github.com/tg123/sshpiper (Go) May 14, 2024
pgibson1-godaddy mtrop-godaddy
Improper escaping in Apache Zeppelin Moderate
CVE-2024-31866 was published for org.apache.zeppelin:zeppelin-interpreter (Maven) Apr 9, 2024
raboof
Drupal core Cross-site Scripting (XSS) vulnerability Moderate
CVE-2020-13672 was published for drupal/core (Composer) Feb 12, 2022
XML External Entity (XXE) in Django Moderate
CVE-2013-1665 was published for Django (pip) May 17, 2022
MarkLee131
Denial of service in django Moderate
CVE-2011-4137 was published for django (pip) Jul 23, 2018
MarkLee131
Kwik does not discard unused encryption keys Moderate
CVE-2024-22588 was published for tech.kwik:kwik (Maven) May 24, 2024
Jenkins Report Info Plugin Path Traversal vulnerability Moderate
CVE-2024-5273 was published for org.jenkins-ci.plugins:report-info (Maven) May 24, 2024
PHP Server Monitor vulnerable to Cross-site Scripting Moderate
CVE-2024-5312 was published for phpservermon/phpservermon (Composer) May 24, 2024
OpenStack Identity (Keystone) Denial of Service Moderate
CVE-2013-2014 was published for keystone (pip) May 13, 2022
MoinMoin Multiple cross-site scripting (XSS) vulnerabilities Moderate
CVE-2007-0857 was published for moin (pip) May 1, 2022
Apache Airflow: XSS vulnerability in Task Instance Log/Log Details Moderate
CVE-2024-32077 was published for apache-airflow (pip) May 14, 2024
OpenStack Glance Server-Side Request Forgery (SSRF) Moderate
CVE-2017-7200 was published for glance (pip) May 17, 2022
Mantis Bug Tracker (MantisBT) vulnerable to cross-site scripting Moderate
CVE-2024-34081 was published for mantisbt/mantisbt (Composer) May 13, 2024
atrol unboundeduniverse
dregad
Bouncy Castle Denial of Service (DoS) Moderate
CVE-2023-33202 was published for org.bouncycastle:bcpkix-jdk18on (Maven) Nov 23, 2023
ind-team ebickle
Ghcml mpihelgas
silverstripe/framework ReadOnly transformation for formfields exploitable Moderate
GHSA-97jm-g33h-f46g was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter Moderate
GHSA-mpqj-f4v3-334h was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing CSRF protection in login form Moderate
GHSA-vj2j-6g3w-4662 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in CMS Edit Page Moderate
GHSA-m8v7-x398-pxrf was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers Moderate
GHSA-87pf-7x99-5xc4 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter Moderate
GHSA-2hpc-mf4q-j885 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing security check on dev/build/defaults Moderate
GHSA-x5w2-wcr8-9q45 was published for silverstripe/framework (Composer) May 23, 2024
ASA-2024-002: Default `PrepareProposalHandler` may produce invalid proposals when used with default `SenderNonceMempool` Moderate
GHSA-2557-x9mg-76w8 was published for github.com/cosmos/cosmos-sdk (Go) Feb 21, 2024
gitferry SebastianElvis
vitsalis
Silverstripe HtmlEditor embed url sanitisation Moderate
GHSA-qp29-wcc2-vmpc was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Form field validation message XSS vulnerability Moderate
GHSA-j982-5jv7-v43r was published for silverstripe/framework (Composer) May 23, 2024
ProTip! Advisories are also available from the GraphQL API