GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,912 advisories
Filter by severity
ecdh vulnerable to Exposure of Resource to Wrong Sphere
High
CVE-2022-44310
was published
for
ecdh
(npm)
Feb 24, 2023
Sequelize - Default support for “raw attributes” when using parentheses
Critical
CVE-2023-22578
was published
for
@sequelize/core
(npm)
Feb 24, 2023
RestEasy Reactive implementation of Quarkus allows Creation of Temporary File With Insecure Permissions
Low
CVE-2023-0481
was published
for
io.quarkus.resteasy.reactive:resteasy-reactive-common
(Maven)
Feb 24, 2023
XML External Entity (XXE) vulnerability in apoc.import.graphml
Moderate
GHSA-9vx8-f5c4-862x
was published
for
org.neo4j.procedure:apoc
(Maven)
Feb 24, 2023
Race Condition Enabling Link Following and Time-of-check Time-of-use (TOCTOU) Race Condition in remove_dir_all
Low
GHSA-mc8h-8q98-g5hr
was published
for
remove_dir_all
(Rust)
Feb 24, 2023
LiteDB may deserialize bad JSON on object type using _type
Critical
CVE-2022-23535
was published
for
LiteDB
(NuGet)
Feb 24, 2023
Apache Airflow Google Provider Improper Input Validation vulnerability
Critical
CVE-2023-25691
was published
for
apache-airflow-providers-google
(pip)
Feb 24, 2023
Apache Airflow Hive Provider Improper Input Validation vulnerability
Critical
CVE-2023-25696
was published
for
apache-airflow-providers-apache-hive
(pip)
Feb 24, 2023
Apache Airflow AWS Provider Generates Error Message Containing Sensitive Information
High
CVE-2023-25956
was published
for
apache-airflow-providers-amazon
(pip)
Feb 24, 2023
Apache Airflow Google Provider Improper Input Validation vulnerability
High
CVE-2023-25692
was published
for
apache-airflow-providers-google
(pip)
Feb 24, 2023
Apache Airflow Sqoop Provider Improper Input Validation vulnerability
Critical
CVE-2023-25693
was published
for
apache-airflow-providers-apache-sqoop
(pip)
Feb 24, 2023
@braintree/sanitize-url Cross-site Scripting vulnerability
Moderate
CVE-2022-48345
was published
for
@braintree/sanitize-url
(npm)
Feb 24, 2023
rangy vulnerable to Prototype Pollution
High
CVE-2023-26102
was published
for
rangy
(npm)
Feb 24, 2023
RosarioSIS Improper Access Control vulnerability
High
CVE-2023-0994
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 24, 2023
Code injection in pdf_info
Critical
CVE-2022-36231
was published
for
pdf_info
(RubyGems)
Feb 24, 2023
Update share links to use FRP instead of SSH tunneling
Moderate
CVE-2023-25823
was published
for
gradio
(pip)
Feb 23, 2023
Undertow client not checking server identity presented by server certificate in https connections
Critical
CVE-2022-4492
was published
for
io.undertow:undertow-core
(Maven)
Feb 23, 2023
Cross-site Scripting in Quarkus
Moderate
CVE-2023-0044
was published
for
io.quarkus:quarkus-vertx-http
(Maven)
Feb 23, 2023
MantisBT may expose private issues' summaries to unauthorized users
Moderate
CVE-2023-22476
was published
for
mantisbt/mantisbt
(Composer)
Feb 23, 2023
Unsafe fall-through in getWhereConditions
Critical
CVE-2023-22579
was published
for
@sequelize/core
(npm)
Feb 23, 2023
OpenNMS Meridian and Horizon vulnerable to Cross-site Scripting
Moderate
CVE-2023-0868
was published
for
org.opennms:opennms-webapp
(Maven)
Feb 23, 2023
OpenNMS has potential Insertion of Sensitive Information into Log File vulnerability
Moderate
CVE-2023-0815
was published
for
org.opennms:opennms
(Maven)
Feb 23, 2023
OpenNMS Meridian and Horizon vulnerable to Cross-site Scripting
Moderate
CVE-2023-0867
was published
for
org.opennms:opennms
(Maven)
Feb 23, 2023
Cross Site Scripting in OpenNMS
Moderate
CVE-2023-0869
was published
for
org.opennms:opennms-web-api
(Maven)
Feb 23, 2023
Improper Privilege Management in Apache Sling
Moderate
CVE-2023-25621
was published
for
org.apache.sling:org.apache.sling.i18n
(Maven)
Feb 23, 2023
ProTip!
Advisories are also available from the
GraphQL API