GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,889 advisories
Filter by severity
Cross-site Scripting in pimcore
Moderate
CVE-2023-0827
was published
for
pimcore/pimcore
(Composer)
Feb 14, 2023
XML External Entity Reference in ureport
High
CVE-2023-24187
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 14, 2023
Cross-Site-Scripting attack on `<RichTextField>`
Moderate
CVE-2023-25572
was published
for
ra-ui-materialui
(npm)
Feb 14, 2023
Vulnerable OpenSSL included in sgx-dcap-quote-verify-python
High
GHSA-344m-qcjq-xgrf
was published
for
sgx-dcap-quote-verify-python
(pip)
Feb 14, 2023
Arbitrary file deletion in ureport
Critical
CVE-2023-24188
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 13, 2023
Cross-site scripting in CKEditor5
Moderate
CVE-2022-48110
was published
for
ckeditor5
(npm)
Feb 13, 2023
•
withdrawn
SameSite Attribute vulnerability in pimCore
High
CVE-2023-25240
was published
for
pimcore/pimcore
(Composer)
Feb 13, 2023
Cross-site Scripting in UDX Stateless Media Plugin
Moderate
CVE-2022-4905
was published
for
wpcloud/wp-stateless
(Composer)
Feb 13, 2023
Path traversal vulnerability in glance
Moderate
CVE-2022-25937
was published
for
glance
(npm)
Feb 13, 2023
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
Moderate
CVE-2023-25727
was published
for
phpmyadmin/phpmyadmin
(Composer)
Feb 13, 2023
Cross-site Scripting in thorsten/phpmyfaq
Moderate
CVE-2023-0786
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq
Moderate
CVE-2023-0787
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Command Injection in thorsten/phpmyfaq
Critical
CVE-2023-0789
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq
Moderate
CVE-2023-0791
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Cross-site Scripting in thorsten/phpmyfaq
Moderate
CVE-2023-0794
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Code Injection in thorsten/phpmyfaq
Critical
CVE-2023-0788
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Uncaught Exception in thorsten/phpmyfaq
High
CVE-2023-0790
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Code Injection in thorsten/phpmyfaq
Moderate
CVE-2023-0792
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Regular Expression Denial of Service in simple-markdown
High
CVE-2019-25102
was published
for
simple-markdown
(npm)
Feb 12, 2023
Weak Password Requirements in thorsten/phpmyfaq
High
CVE-2023-0793
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Regular Expression Denial of Service in simple-markdown
High
CVE-2019-25103
was published
for
simple-markdown
(npm)
Feb 12, 2023
Improper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpit
Moderate
CVE-2023-0780
was published
for
cockpit-hq/cockpit
(Composer)
Feb 11, 2023
Withdrawn: cacheable-request depends on http-cache-semantics, which is vulnerable to Regular Expression Denial of Service
High
GHSA-8x6c-cv3v-vp6g
was published
for
cacheable-request
(npm)
Feb 11, 2023
•
withdrawn
Arbitrary code execution in de.tum.in.ase:artemis-java-test-sandbox
High
GHSA-98hq-4wmw-98w9
was published
for
de.tum.in.ase:artemis-java-test-sandbox
(Maven)
Feb 10, 2023
Pterodactyl Wings contains UNIX Symbolic Link (Symlink) Following resulting in deletion of files and directories on the host system
Critical
CVE-2023-25168
was published
for
github.com/pterodactyl/wings
(Go)
Feb 10, 2023
ProTip!
Advisories are also available from the
GraphQL API