GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,358 advisories
Filter by severity
Awesome Support vulnerable to persistent cross-site scripting
Moderate
CVE-2022-38073
was published
for
awesome-support/awesome-support
(Composer)
Sep 22, 2022
rdiffweb CSRF could lead to disabling notifications in user profile
Moderate
CVE-2022-3233
was published
for
rdiffweb
(pip)
Sep 22, 2022
autogluon.multimodal vulnerable to unsafe YAML deserialization
High
GHSA-6h2x-4gjf-jc5w
was published
for
autogluon.multimodal
(pip)
Sep 21, 2022
@netlify/ipx vulnerable to Full Response SSRF and Stored XSS via Cache Poisoning and Improper Host Validation
Moderate
CVE-2022-39239
was published
for
@netlify/ipx
(npm)
Sep 21, 2022
python-jwt vulnerable to token forgery with new claims
Critical
CVE-2022-39227
was published
for
python-jwt
(pip)
Sep 21, 2022
parse-server auth adapter app ID validation can be circumvented
Low
CVE-2022-39231
was published
for
parse-server
(npm)
Sep 21, 2022
fhir-works-on-aws-authz-smart handles permissions improperly
Moderate
CVE-2022-39230
was published
for
fhir-works-on-aws-authz-smart
(npm)
Sep 21, 2022
parse-server's session object properties can be updated by foreign user if object ID is known
Moderate
CVE-2022-39225
was published
for
parse-server
(npm)
Sep 21, 2022
Unbounded resource exhaustion in cmark-gfm autolink extension may lead to denial of service
Moderate
GHSA-4qw4-jpp4-8gvp
was published
for
commonmarker
(RubyGems)
Sep 21, 2022
arr-pm vulnerable to arbitrary shell execution when extracting or listing files contained in a malicious rpm.
High
CVE-2022-39224
was published
for
arr-pm
(RubyGems)
Sep 21, 2022
jwcrypto token substitution can lead to authentication bypass
Moderate
CVE-2022-3102
was published
for
jwcrypto
(pip)
Sep 21, 2022
personnummer/rust vulnerable to Improper Input Validation
Low
GHSA-28r9-pq4c-wp3c
was published
for
personnummer
(Rust)
Sep 21, 2022
YetiForce CRM vulnerable to stored Cross-site Scripting via WorkFlow module
Moderate
CVE-2022-3004
was published
for
yetiforce/yetiforce-crm
(Composer)
Sep 21, 2022
Microweber Cross-site Scripting can result in redirection to a malicious site
Moderate
CVE-2022-3242
was published
for
microweber/microweber
(Composer)
Sep 21, 2022
YetiForce CRM vulnerable to stored Cross-site Scripting via LayoutEditor module
Moderate
CVE-2022-3000
was published
for
yetiforce/yetiforce-crm
(Composer)
Sep 21, 2022
Apache Kafka vulnerability can lead to brokers hitting OutOfMemoryException, causing Denial of Service
High
CVE-2022-34917
was published
for
org.apache.kafka:kafka
(Maven)
Sep 21, 2022
YetiForce CRM vulnerable to stored Cross-site Scripting via WidgetsManagement module
Moderate
CVE-2022-2924
was published
for
yetiforce/yetiforce-crm
(Composer)
Sep 21, 2022
YetiForce CRM vulnerable to stored Cross-site Scripting via SlaPolicy module
Moderate
CVE-2022-3005
was published
for
yetiforce/yetiforce-crm
(Composer)
Sep 21, 2022
Apache InLong vulnerable to Deserialization of Untrusted Data
High
CVE-2022-40955
was published
for
org.apache.inlong:inlong-common
(Maven)
Sep 21, 2022
Microweber vulnerable to HTML Injection in create tag functionality
Moderate
CVE-2022-3245
was published
for
microweber/microweber
(Composer)
Sep 21, 2022
Cross site scripting in Cloudreve
Moderate
CVE-2022-32167
was published
for
github.com/HFO4/cloudreve
(Go)
Sep 21, 2022
Pagekit vulnerable to Unrestricted Upload of File with Dangerous Type
Critical
CVE-2022-38916
was published
for
pagekit/pagekit
(Composer)
Sep 21, 2022
steal Inefficient Regular Expression Complexity vulnerability via string variable
High
CVE-2022-37259
was published
for
steal
(npm)
Sep 21, 2022
steal vulnerable to Prototype Pollution via alias variable
Critical
CVE-2022-37265
was published
for
steal
(npm)
Sep 21, 2022
WASM3 Improper Input Validation vulnerability
High
CVE-2022-39974
was published
for
pywasm3
(pip)
Sep 21, 2022
ProTip!
Advisories are also available from the
GraphQL API