GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,358 advisories
Filter by severity
SFTPGo WebClient vulnerable to Cross-site Scripting
Moderate
CVE-2022-39220
was published
for
github.com/drakkan/sftpgo
(Go)
Sep 20, 2022
XWiki.WebHome vulnerable to Improper Privilege Management in XWiki resolving groups
High
CVE-2022-31166
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Sep 20, 2022
XWiki Platform Security Parent POM vulnerable to overwriting of security rules of a page with a final page having the same reference
High
CVE-2022-31167
was published
for
org.xwiki.platform:xwiki-platform-security
(Maven)
Sep 20, 2022
Fastly Compute@Edge JS Runtime has fixed random number seed during compilation
High
CVE-2022-39218
was published
for
@fastly/js-compute
(npm)
Sep 20, 2022
CRI-O incorrect handling of supplementary groups may lead to sensitive information disclosure
High
CVE-2022-2995
was published
for
github.com/cri-o/cri-o
(Go)
Sep 20, 2022
Valine code injection vulnerability
Critical
CVE-2022-38545
was published
for
valine
(npm)
Sep 20, 2022
personnummer/dart vulnerable to Improper Input Validation
Low
CVE-2023-22963
was published
for
personnummer
(Pub)
Sep 19, 2022
Vuetify Cross-site Scripting vulnerability
Moderate
CVE-2022-25873
was published
for
org.webjars.npm:vuetify
(Maven)
Sep 19, 2022
LibreNMS stored Cross-site Scripting via Schedule Maintenance `Title` parameter
Moderate
CVE-2022-3231
was published
for
librenms/librenms
(Composer)
Sep 18, 2022
Snipe-IT vulnerable to Improper Authentication
Moderate
CVE-2022-3173
was published
for
snipe/snipe-it
(Composer)
Sep 18, 2022
rdiffweb CSRF vulnerability in admin area can lead to deletion of repositories and users
Moderate
CVE-2022-3232
was published
for
rdiffweb
(pip)
Sep 18, 2022
Jettison parser crash by stackoverflow
Moderate
CVE-2022-40149
was published
for
org.codehaus.jettison:jettison
(Maven)
Sep 17, 2022
Jettison memory exhaustion
High
CVE-2022-40150
was published
for
org.codehaus.jettison:jettison
(Maven)
Sep 17, 2022
Denial of Service via stack overflow
Low
CVE-2022-40155
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
•
withdrawn
Denial of Service due to parser crash
High
CVE-2022-40153
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
•
withdrawn
Denial of Service via stack overflow
Low
CVE-2022-40154
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
•
withdrawn
Denial of Service due to parser crash
Low
CVE-2022-40156
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
•
withdrawn
Duplicate Advisory: Denial of Service due to parser crash
Low
GHSA-3mq5-fq9h-gj7j
was published
for
com.thoughtworks.xstream:xstream
(Maven)
Sep 17, 2022
•
withdrawn
Denial of Service due to parser crash
Moderate
CVE-2022-40152
was published
for
com.fasterxml.woodstox:woodstox-core
(Maven)
Sep 17, 2022
Craft CMS Cross site Scripting vulnerability
Moderate
CVE-2022-37248
was published
for
craftcms/cms
(Composer)
Sep 17, 2022
Craft CMS Stored Cross-site Scripting in User Addresses Title
Moderate
CVE-2022-37250
was published
for
craftcms/cms
(Composer)
Sep 17, 2022
Budibase Improper Access Control vulnerability
Moderate
CVE-2022-3225
was published
for
@budibase/bbui
(npm)
Sep 17, 2022
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
Moderate
CVE-2022-37251
was published
for
craftcms/cms
(Composer)
Sep 17, 2022
Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page
Moderate
CVE-2022-37247
was published
for
craftcms/cms
(Composer)
Sep 17, 2022
steal vulnerable to Prototype Pollution
Critical
CVE-2022-37258
was published
for
steal
(npm)
Sep 17, 2022
ProTip!
Advisories are also available from the
GraphQL API