GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,437
Maven
5,000+
npm
5,000+
NuGet
883
pip
4,695
Pub
13
RubyGems
1,031
Rust
1,222
Swift
53
Unreviewed advisories
All unreviewed
5,000+
4,451 advisories
Filter by severity
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account...
High
Unreviewed
CVE-2021-39114
was published
Apr 6, 2022
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured...
Moderate
Unreviewed
CVE-2021-27493
was published
Apr 3, 2022
Command injection in cocoapods-downloader
High
CVE-2022-21223
was published
for
cocoapods-downloader
(RubyGems)
Apr 2, 2022
Command injection in cocoapods-downloader
High
CVE-2022-24440
was published
for
cocoapods-downloader
(RubyGems)
Apr 2, 2022
Remote Code Execution in Spring Framework
Critical
CVE-2022-22965
was published
for
org.springframework.boot:spring-boot-starter-web
(Maven)
Mar 31, 2022
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction...
High
Unreviewed
CVE-2021-43097
was published
Mar 30, 2022
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This...
Critical
Unreviewed
CVE-2022-25420
was published
Mar 30, 2022
Sonatype Nexus Repository Manager 3.36.0 allows HTML Injection.
Moderate
Unreviewed
CVE-2021-43961
was published
Mar 19, 2022
Command injection in libvcs and vcspull
Critical
CVE-2022-21187
was published
for
libvcs
(pip)
Mar 15, 2022
Command injection in Parse Server through prototype pollution
Critical
CVE-2022-24760
was published
for
parse-server
(npm)
Mar 11, 2022
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection)...
Critical
Unreviewed
CVE-2022-24442
was published
Feb 26, 2022
A potential remote host header injection security vulnerability has been identified in HPE...
Moderate
Unreviewed
CVE-2022-23701
was published
Feb 25, 2022
Authenticated remote code execution in October CMS
High
CVE-2022-21705
was published
for
october/system
(Composer)
Feb 23, 2022
Cryptomator through 1.6.5 allows DYLIB injection because, although it has the flag 0x1000 for...
High
Unreviewed
CVE-2022-25366
was published
Feb 20, 2022
Code injection in ezsystems/ezpublish-kernel
Critical
CVE-2022-25337
was published
for
ezsystems/ezpublish-kernel
(Composer)
Feb 19, 2022
Server Side Template Injection in MCMS
Critical
CVE-2021-46063
was published
for
net.mingsoft:ms-mcms
(Maven)
Feb 19, 2022
Minetest before 5.4.0 allows attackers to add or modify arbitrary meta fields of the same item...
Critical
Unreviewed
CVE-2022-24300
was published
Feb 15, 2022
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11...
Critical
Unreviewed
CVE-2022-0582
was published
Feb 15, 2022
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial...
High
Unreviewed
CVE-2022-0581
was published
Feb 15, 2022
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical...
High
Unreviewed
CVE-2020-12965
was published
Feb 11, 2022
A flaw was found in Python, specifically within the urllib.parse module. This module helps break...
High
Unreviewed
CVE-2022-0391
was published
Feb 11, 2022
Improper file handling in matrix-react-sdk
Moderate
CVE-2021-32622
was published
for
matrix-react-sdk
(npm)
Feb 10, 2022
Injection in Apache Archiva
Moderate
CVE-2020-9495
was published
for
org.apache.archiva:archiva
(Maven)
Feb 10, 2022
ProTip!
Advisories are also available from the
GraphQL API