GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,069
Maven
5,000+
npm
3,744
NuGet
668
pip
3,429
Pub
12
RubyGems
892
Rust
880
Swift
36
Unreviewed advisories
All unreviewed
5,000+
89 advisories
Filter by severity
Authentication Bypass by Alternate Name in Apache Tomcat
Moderate
CVE-2021-30640
was published
for
org.apache.tomcat:tomcat
(Maven)
Aug 13, 2021
IBM Cloud Pak for Automation 21.0.1 and 21.0.2 - Business Automation Studio Component is...
Moderate
Unreviewed
CVE-2021-29872
was published
Jan 19, 2022
A Header Injection vulnerability exists in Compass Plus TranzWare Online FIMI Web Interface...
Moderate
Unreviewed
CVE-2021-43106
was published
Feb 15, 2022
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection...
Moderate
Unreviewed
CVE-2022-45102
was published
Feb 1, 2023
A vulnerability exists where the caret ("^") character is improperly escaped constructing some...
Moderate
Unreviewed
CVE-2019-11717
was published
May 24, 2022
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the...
Moderate
Unreviewed
CVE-2023-0595
was published
Feb 24, 2023
The Featured Image from URL (FIFU) WordPress plugin before 4.0.0 does not have CSRF check in...
Moderate
Unreviewed
CVE-2022-2241
was published
Aug 2, 2022
Path traversal in xwiki-platform-skin-skinx
Moderate
CVE-2022-23620
was published
for
org.xwiki.platform:xwiki-platform-skin-skinx
(Maven)
Feb 9, 2022
The Simple Quotation WordPress plugin through 1.3.2 does not have CSRF check when creating or...
Moderate
Unreviewed
CVE-2022-22734
was published
Mar 15, 2022
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to...
Moderate
Unreviewed
CVE-2022-0210
was published
Jan 19, 2022
The check_privacy_settings AJAX action of the WordPress GDPR WordPress plugin before 1.9.27,...
Moderate
Unreviewed
CVE-2022-0220
was published
Feb 2, 2022
Cross-site Scripting in Jenkins Random String Parameter Plugin
Moderate
CVE-2022-30966
was published
for
org.jenkins-ci.plugins:random-string-parameter
(Maven)
May 18, 2022
The Menu Image, Icons made easy WordPress plugin before 3.0.8 does not have authorisation and...
Moderate
Unreviewed
CVE-2022-0450
was published
Mar 29, 2022
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation...
Moderate
Unreviewed
CVE-2022-0421
was published
Nov 21, 2022
WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection
Moderate
CVE-2022-2099
was published
for
woocommerce/woocommerce
(Composer)
Jul 18, 2022
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug...
Moderate
Unreviewed
CVE-2021-31806
was published
May 24, 2022
An issue was discovered in COINS Construction Cloud 11.12. Due to improper validation of user...
Moderate
Unreviewed
CVE-2021-45226
was published
Jan 25, 2022
OpenZeppelin Contracts vulnerable to Improper Escaping of Output
Moderate
CVE-2023-40014
was published
for
@openzeppelin/contracts
(npm)
Aug 11, 2023
Teampass Cross-site Scripting vulnerability
Moderate
CVE-2023-3190
was published
for
nilsteampassnet/teampass
(Composer)
Jun 10, 2023
Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
Moderate
CVE-2023-34036
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jul 17, 2023
Critters Cross-site Scripting Vulnerability
Moderate
CVE-2023-3481
was published
for
critters
(npm)
Aug 11, 2023
Mattermost password hash disclosure vulnerability
Moderate
CVE-2023-5968
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Nov 6, 2023
Improper Encoding or Escaping of Output in Jenkins Configuration as Code Plugin
Moderate
CVE-2019-10362
was published
for
io.jenkins:configuration-as-code
(Maven)
May 24, 2022
Stored XSS vulnerability in Jenkins Git Plugin
Moderate
CVE-2021-21684
was published
for
org.jenkins-ci.plugins:git
(Maven)
May 24, 2022
lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization,...
Moderate
Unreviewed
CVE-2023-42183
was published
Dec 15, 2023
ProTip!
Advisories are also available from the
GraphQL API