GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
37
Go
2,526
Maven
5,000+
npm
4,189
NuGet
742
pip
3,968
Pub
12
RubyGems
947
Rust
1,030
Swift
39
Unreviewed advisories
All unreviewed
5,000+
24,030 advisories
Filter by severity
static-dev-server vulnerable to path traversal
High
CVE-2022-25848
was published
for
static-dev-server
(npm)
Nov 29, 2022
Package discontinued because Bitly lowered the free quota
Low
GHSA-ggrh-grj3-vfvw
was published
for
bitlyshortener
(pip)
Nov 28, 2022
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Moderate
CVE-2022-39325
was published
for
baserproject/basercms
(Composer)
Nov 28, 2022
Temporary File Information Disclosure vulnerability in MPXJ
Low
CVE-2022-41954
was published
for
mpxj
(Maven)
Nov 28, 2022
code injection in phpxmlrpc/phpxmlrpc
High
GHSA-3fgr-xjr6-xqm8
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Nov 28, 2022
ghost vulnerable to unauthorized newsletter modification via improper access controls
High
CVE-2022-41654
was published
for
ghost
(npm)
Nov 28, 2022
FusionAuth vulnerable to directory traversal attack
High
CVE-2022-45921
was published
for
io.fusionauth:fusionauth-java-client
(Maven)
Nov 28, 2022
decode-uri-component vulnerable to Denial of Service (DoS)
High
CVE-2022-38900
was published
for
decode-uri-component
(npm)
Nov 28, 2022
KubeView vulnerable to full cluster takeover due to improper authentication
Critical
CVE-2022-45933
was published
for
github.com/benc-uk/kubeview
(Go)
Nov 27, 2022
PaddlePaddle vulnerable to code injection via winstr
Critical
CVE-2022-45908
was published
for
paddlepaddle
(pip)
Nov 26, 2022
PyTorch vulnerable to arbitrary code execution
Critical
CVE-2022-45907
was published
for
torch
(pip)
Nov 26, 2022
Moodle blind Server-Side Request Forgery (SSRF) vulnerability in LTI provider library
Critical
CVE-2022-45152
was published
for
moodle/moodle
(Composer)
Nov 25, 2022
Microweber vulnerable to cross-site scripting (XSS)
Moderate
CVE-2022-0698
was published
for
microweber/microweber
(Composer)
Nov 25, 2022
PyroCMS vulnerable to stored Cross Site Scripting
Critical
CVE-2022-37721
was published
for
pyrocms/pyrocms
(Composer)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via /sys/user/putRecycleBin
Moderate
CVE-2022-45208
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL Injection
Critical
CVE-2022-45206
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL injection via updateNullByEmptyString
Critical
CVE-2022-45207
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Jeecg-boot vulnerable to SQL Injection
Moderate
CVE-2022-45210
was published
for
org.jeecgframework.boot:jeecg-module-system
(Maven)
Nov 25, 2022
Browsershot does not validate URL protocols passed to Browsershot URL method
High
CVE-2022-41706
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
Badaso vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-41705
was published
for
badaso/core
(Composer)
Nov 25, 2022
Browsershot vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2022-43983
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
Browsershot version 3.57.3 vulnerable to improper input validation
Moderate
CVE-2022-43984
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
Apache Dolphin Scheduler has insufficiently protected credentials
High
CVE-2022-26885
was published
for
org.apache.dolphinscheduler:dolphinscheduler-common
(Maven)
Nov 24, 2022
ProTip!
Advisories are also available from the
GraphQL API