GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,802
Erlang
36
GitHub Actions
29
Go
2,382
Maven
5,000+
npm
4,015
NuGet
720
pip
3,811
Pub
12
RubyGems
930
Rust
987
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,188 advisories
Filter by severity
UniSharp Laravel Filemanager directory traversal vulnerability
Moderate
CVE-2022-40734
was published
for
unisharp/laravel-filemanager
(Composer)
Sep 15, 2022
rdiffweb Missing Custom Error Page
Moderate
CVE-2022-3175
was published
for
rdiffweb
(pip)
Sep 14, 2022
rdiffweb vulnerable to Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
High
CVE-2022-3174
was published
for
rdiffweb
(pip)
Sep 14, 2022
Podman's incorrect handling of the supplementary groups may lead to data disclosure, modification
High
CVE-2022-2989
was published
for
github.com/containers/podman/v3
(Go)
Sep 14, 2022
WildFly vulnerable to Insecure Default Initialization of Resource
High
CVE-2022-1278
was published
for
org.wildfly.bom:wildfly
(Maven)
Sep 14, 2022
Buildah's incorrect handling of the supplementary groups may lead to data disclosure, modification
High
CVE-2022-2990
was published
for
github.com/containers/buildah
(Go)
Sep 14, 2022
CrafterCMS Crafter Studio Improperly Controls Dynamically-Managed Code Resources
High
CVE-2022-40634
was published
for
org.craftercms:crafter-studio
(Maven)
Sep 14, 2022
CrafterCMS OS Command Injection vulnerability
High
CVE-2022-40635
was published
for
org.craftercms:craftercms
(Maven)
Sep 14, 2022
rdiffweb contains Weak Password Requirements
High
CVE-2022-3179
was published
for
rdiffweb
(pip)
Sep 14, 2022
NLnet Labs Routinator has Reachable Assertion vulnerability
High
CVE-2022-3029
was published
for
routinator
(Rust)
Sep 14, 2022
LIEF vulnerable to heap based buffer overflow via print_binary function
High
CVE-2022-38495
was published
for
lief
(pip)
Sep 14, 2022
LIEF contains a segmentation violation
Moderate
CVE-2022-38497
was published
for
lief
(pip)
Sep 14, 2022
LIEF vulnerable to heap based buffer overflow
Moderate
CVE-2022-38306
was published
for
lief
(pip)
Sep 14, 2022
LIEF contains segmentation violation
Moderate
CVE-2022-38307
was published
for
lief
(pip)
Sep 14, 2022
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2021-36568
was published
for
moodle/moodle
(Composer)
Sep 14, 2022
Pebble Templates protection mechanism bypass can lead to arbitrary code execution
Critical
CVE-2022-37767
was published
for
io.pebbletemplates:pebble
(Maven)
Sep 13, 2022
graphql-java vulnerable to Denial of Service via GraphQL query that consumes CPU resources
High
CVE-2022-37734
was published
for
com.graphql-java:graphql-java
(Maven)
Sep 13, 2022
Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack
Critical
CVE-2022-39135
was published
for
org.apache.calcite:calcite-core
(Maven)
Sep 12, 2022
Gophish before 0.12.0 vulnerable to Open Redirect
Moderate
CVE-2022-25295
was published
for
github.com/gophish/gophish
(Go)
Sep 12, 2022
Goomph before 3.37.2 allows malicious zip file to write contents to arbitrary locations
High
CVE-2022-26049
was published
for
com.diffplug.gradle:goomph
(Maven)
Sep 12, 2022
PDFKit vulnerable to Command Injection
Critical
CVE-2022-25765
was published
for
pdfkit
(RubyGems)
Sep 10, 2022
Appwrite Vulnerable to Cross-site Scripting
Moderate
CVE-2022-2925
was published
for
appwrite/server-ce
(Composer)
Sep 10, 2022
Rank Math SEO plugin vulnerable to Server-Side Request Forgery
Critical
CVE-2022-36376
was published
for
rankmath/seo-by-rank-math
(Composer)
Sep 10, 2022
Markdown-Nice v1.8.22 vulnerable to Cross-site Scripting
Moderate
CVE-2022-38639
was published
for
markdown-nice
(npm)
Sep 10, 2022
Casdoor arbitrary file write vulnerability
Critical
CVE-2022-38638
was published
for
github.com/casdoor/casdoor
(Go)
Sep 10, 2022
ProTip!
Advisories are also available from the
GraphQL API