GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
835
Go
441
Maven
1,201
npm
2,405
NuGet
174
pip
1,054
RubyGems
462
Rust
397
Unreviewed advisories
All unreviewed
5,000+
6,934 advisories
Filter by severity
Persistent Cross-site Scripting vulnerability in PrivateBin
High
CVE-2022-24833
was published
for
privatebin/privatebin
(Composer)
Apr 12, 2022
Improper Certificate Validation
High
CVE-2017-11770
was published
for
Microsoft.NETCore.App
(NuGet)
Apr 12, 2022
Denial of Service (DoS) in Nokogiri on JRuby
High
GHSA-gx8x-g87m-h5q6
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
XML Injection in Xerces Java affects Nokogiri
Moderate
GHSA-xxx9-3xcr-gjj3
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
Out-of-bounds Write in zlib affects Nokogiri
High
GHSA-v6gp-9mmm-c6p5
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
Inefficient Regular Expression Complexity in Nokogiri
High
CVE-2022-24836
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
Remote Code Execution in Laravel
Moderate
CVE-2021-43503
was published
for
laravel/laravel
(Composer)
Apr 9, 2022
SQL Injection in elide-datastore-aggregation
High
CVE-2022-24827
was published
for
com.yahoo.elide:elide-datastore-aggregation
(Maven)
Apr 8, 2022
Daemon panics when processing certain blocks
High
GHSA-mcq2-w56r-5w2w
was published
for
github.com/ipld/go-ipfs
(Go)
Apr 8, 2022
Panic when processing certain blocks
Moderate
GHSA-g3vv-g2j5-45f2
was published
for
github.com/ipld/go-codec-dagpb
(Go)
Apr 8, 2022
Unauthenticated user can list hidden document from multiple velocity templates
Moderate
CVE-2022-24820
was published
for
org.xwiki.platform:xwiki-platform-web
(Maven)
Apr 8, 2022
Incorrect Use of Privileged APIs in org.xwiki.platform.skin.skinx
Moderate
CVE-2022-24821
was published
for
org.xwiki.platform:xwiki-platform-skin-skinx
(Maven)
Apr 8, 2022
Unauthenticated user can retrieve the list of users through uorgsuggest.vm
Moderate
CVE-2022-24819
was published
for
org.xwiki.platform:xwiki-platform-web-templates
(Maven)
Apr 8, 2022
Infinite loop in .Net Bond
High
CVE-2020-1469
was published
for
Bond.Core.CSharp
(NuGet)
Apr 8, 2022
Insecure temporary file usage in SWHKD
Moderate
CVE-2022-27818
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 8, 2022
Unsafe parsing in SWHKD
Moderate
CVE-2022-27819
was published
for
Simple-Wayland-HotKey-Daemon
(Rust)
Apr 8, 2022
Path traversal in Hadoop
Moderate
CVE-2022-26612
was published
for
org.apache.hadoop:hadoop-common
(Maven)
Apr 8, 2022
Smokescreen SSRF via deny list bypass
Moderate
CVE-2022-24825
was published
for
github.com/stripe/smokescreen
(Go)
Apr 7, 2022
Improper one time password handling in devise-two-factor
High
CVE-2021-43177
was published
for
devise-two-factor
(RubyGems)
Apr 7, 2022
Denial of Service vulnerability in @podium/layout and @podium/proxy
High
CVE-2022-24822
was published
for
@podium/layout
(npm)
Apr 7, 2022
SQL Injection when creating an application with Reactive SQL backend
High
CVE-2022-24815
was published
for
generator-jhipster
(npm)
Apr 7, 2022
HTTP Proxy header vulnerability
High
CVE-2016-5385
was published
for
guzzlehttp/guzzle
(Composer)
Apr 7, 2022
SQL injection in net.mingsoft:ms-mcms
High
CVE-2022-26585
was published
for
net.mingsoft:ms-mcms
(Maven)
Apr 6, 2022
Server side request forgery in livehelperchat
High
CVE-2022-1213
was published
for
remdex/livehelperchat
(Composer)
Apr 6, 2022
ProTip!
Advisories are also available from the
GraphQL API

