GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
25,464 advisories
Filter by severity
Allegro Tech BigFlow vulnerable to Missing SSL Certificate Validation
Moderate
CVE-2023-25392
was published
for
bigflow
(pip)
Apr 10, 2023
Apache Linkis JDBC EngineConn has deserialization vulnerability
Critical
CVE-2023-29215
was published
for
org.apache.linkis:linkis-engineconn
(Maven)
Apr 10, 2023
Apache Linkis DatasourceManager module has deserialization vulnerability
Critical
CVE-2023-29216
was published
for
org.apache.linkis:linkis-datasource
(Maven)
Apr 10, 2023
XXL-JOB vulnerable to Cross-site Scripting
Moderate
CVE-2023-26120
was published
for
com.xuxueli:xxl-job
(Maven)
Apr 10, 2023
ntru-rs has unsound FFI: Wrong API usage causes write past allocated area
Moderate
GHSA-fq33-vmhv-48xh
was published
for
ntru
(Rust)
Apr 7, 2023
SvelteKit framework has Insufficient CSRF protection for CORS requests
High
CVE-2023-29008
was published
for
@sveltejs/kit
(npm)
Apr 7, 2023
Goobi viewer Core Reflected Cross-Site Scripting Vulnerability Using LOGID Parameter
Moderate
CVE-2023-29014
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Comments
Moderate
CVE-2023-29015
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Goobi viewer Core has Cross-Site Scripting Vulnerability in User Nicknames
Moderate
CVE-2023-29016
was published
for
io.goobi.viewer:viewer-core
(Maven)
Apr 7, 2023
Apache Airflow Drill Provider vulnerable to improper input validation
High
CVE-2023-28707
was published
for
apache-airflow-providers-apache-drill
(pip)
Apr 7, 2023
Apache Airflow Spark Provider vulnerable to improper input validation
High
CVE-2023-28710
was published
for
apache-airflow-providers-apache-spark
(pip)
Apr 7, 2023
Apache Airflow Hive Provider vulnerable to code injection
Critical
CVE-2023-28706
was published
for
apache-airflow-providers-apache-hive
(pip)
Apr 7, 2023
xml2js is vulnerable to prototype pollution
Moderate
CVE-2023-0842
was published
for
xml2js
(npm)
Apr 5, 2023
HashiCorp Nomad vulnerable to unauthenticated client agent HTTP request privilege escalation
High
CVE-2023-1782
was published
for
github.com/hashicorp/nomad
(Go)
Apr 5, 2023
Firefly III insufficiently expires sessions
Moderate
CVE-2023-1788
was published
for
grumpydictator/firefly-iii
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to authentication bypass
High
CVE-2023-1886
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter
High
CVE-2023-1758
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via category field name parameter
Moderate
CVE-2023-1885
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header
High
CVE-2023-1881
was published
for
microweber/microweber
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to cross-site scripting (XSS) via stopword parameter
Moderate
CVE-2023-1884
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameter
High
CVE-2023-1882
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via adminlog
High
CVE-2023-1878
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via FAQ News link parameter
High
CVE-2023-1757
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via updatecategory parameter
Moderate
CVE-2023-1879
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
ProTip!
Advisories are also available from the
GraphQL API