GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,912 advisories
Filter by severity
Saleor has Staff-Authenticated Error Message Information Disclosure Vulnerability via Python Exceptions
Moderate
CVE-2023-26051
was published
for
Saleor
(pip)
Mar 3, 2023
Craft CMS Stored Cross-site Scripting Injection Vulnerability
Moderate
CVE-2023-23927
was published
for
craftcms/cms
(Composer)
Mar 3, 2023
Opencontainers runc Incorrect Authorization vulnerability
High
CVE-2023-27561
was published
for
github.com/opencontainers/runc
(Go)
Mar 3, 2023
OpenZeppelin Contracts contains Incorrect Calculation
Moderate
CVE-2023-26488
was published
for
@openzeppelin/contracts
(npm)
Mar 3, 2023
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Moderate
CVE-2022-2835
was published
for
github.com/coredns/coredns
(Go)
Mar 3, 2023
coreDNS vulnerable to Improper Restriction of Communication Channel to Intended Endpoints
Moderate
CVE-2022-2837
was published
for
github.com/coredns/coredns
(Go)
Mar 3, 2023
phpseclib Infinite Loop vulnerability
High
CVE-2023-27560
was published
for
phpseclib/phpseclib
(Composer)
Mar 3, 2023
Cockpit Uses Platform-Dependent Third Party Components
Moderate
CVE-2023-1160
was published
for
cockpit-hq/cockpit
(Composer)
Mar 3, 2023
Vega vulnerable to arbitrary code execution when clicking href links
Moderate
GHSA-cp47-r258-q626
was published
for
vega
(npm)
Mar 2, 2023
Keycloak vulnerable to user impersonation via stolen UUID code
High
CVE-2023-0264
was published
for
org.keycloak:keycloak-services
(Maven)
Mar 2, 2023
keycloak-connect contains Open redirect vulnerability in the Node.js adapter
Moderate
CVE-2022-2237
was published
for
keycloak-connect
(npm)
Mar 2, 2023
gosaml2 vulnerable to Denial Of Service Via Deflate Decompression Bomb
Moderate
CVE-2023-26483
was published
for
github.com/russellhaering/gosaml2
(Go)
Mar 2, 2023
Vega Expression Language `scale` expression function Cross Site Scripting
Moderate
CVE-2023-26486
was published
for
vega
(npm)
Mar 2, 2023
Vega has Cross-site Scripting vulnerability in `lassoAppend` function
Moderate
CVE-2023-26487
was published
for
vega
(npm)
Mar 2, 2023
Saleor Unauthenticated Information Disclosure Vulnerability via Python Exceptions
Low
CVE-2023-26052
was published
for
saleor
(pip)
Mar 2, 2023
xwiki-platform vulnerable to Remote Code Execution in Annotations
Critical
CVE-2023-26475
was published
for
org.xwiki.platform:xwiki-platform-annotation-ui
(Maven)
Mar 2, 2023
Pimcore vulnerable to Cross Site Scripting in Email Blacklist
Moderate
CVE-2023-1116
was published
for
pimcore/pimcore
(Composer)
Mar 1, 2023
Pimcore vulnerable to Cross Site Scripting in image/video thumbnail config
Moderate
CVE-2023-1117
was published
for
pimcore/pimcore
(Composer)
Mar 1, 2023
Pimcore vulnerable to Cross Site Scripting in Documents Link Editable
Moderate
CVE-2023-1115
was published
for
pimcore/pimcore
(Composer)
Mar 1, 2023
nistec has Incorrect Calculation in Multiplication of unreduced P-256 scalars
High
CVE-2023-24533
was published
for
filippo.io/nistec
(Go)
Mar 1, 2023
Kubernetes vulnerable to path traversal
Moderate
CVE-2022-3162
was published
for
github.com/kubernetes/kubernetes
(Go)
Mar 1, 2023
Kubernetes vulnerable to validation bypass
High
CVE-2022-3294
was published
for
github.com/kubernetes/kubernetes
(Go)
Mar 1, 2023
Grafana vulnerable to Stored Cross-site Scripting in Text plugin
Moderate
CVE-2023-22462
was published
for
github.com/grafana/grafana
(Go)
Mar 1, 2023
teler-waf contains detection rule bypass via Entities payload
Moderate
CVE-2023-26047
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
teler-waf subject to Bypass of Common Web Attack Threat Rule with HTML Entities Payload
Moderate
CVE-2023-26046
was published
for
github.com/kitabisa/teler-waf
(Go)
Mar 1, 2023
ProTip!
Advisories are also available from the
GraphQL API