GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
23,358 advisories
Filter by severity
Apache Pinot has Groovy Function support enabled by default
Critical
CVE-2022-26112
was published
for
org.apache.pinot:pinot
(Maven)
Sep 25, 2022
Mattermost subject to Denial of Service via upload of special GIF
Moderate
CVE-2022-3257
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Sep 25, 2022
Scala subject to file deletion, code execution due to Java deserialization chain with LazyList object deserialization
Critical
CVE-2022-36944
was published
for
org.scala-lang:scala-library
(Maven)
Sep 25, 2022
Proxy component of Apache Pulsar subject to abuse as Denial of Service endpoint
Moderate
CVE-2022-24280
was published
for
org.apache.pulsar:pulsar
(Maven)
Sep 25, 2022
Nepxion Discovery vulnerable to potential Information Disclosure due to Server-Side Request Forgery
Moderate
CVE-2022-23464
was published
for
com.nepxion:discovery
(Maven)
Sep 25, 2022
secp256k1-js implements ECDSA without required r and s validation, leading to signature forgery
High
CVE-2022-41340
was published
for
@lionello/secp256k1-js
(npm)
Sep 25, 2022
Jodit Editor vulnerable to Cross-site Scripting
Moderate
CVE-2022-23461
was published
for
jodit
(npm)
Sep 25, 2022
Nepxion Discovery vulnerable to SpEL Injection leading to Remote Code Execution
Critical
CVE-2022-23463
was published
for
com.nepxion:discovery
(Maven)
Sep 25, 2022
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions
High
CVE-2021-41803
was published
for
github.com/hashicorp/consul
(Go)
Sep 25, 2022
Weight not properly refunded after EVM execution
Moderate
CVE-2022-39242
was published
for
pallet-ethereum
(Rust)
Sep 23, 2022
Caddy-SSH vulnerable to Authorization Bypass due to incorrect usage of PAM library
High
GHSA-gmhj-xjfh-cf6m
was published
for
github.com/mohammed90/caddy-ssh
(Go)
Sep 23, 2022
protobuf-cpp and protobuf-python have potential Denial of Service issue
High
CVE-2022-1941
was published
for
protobuf
(pip)
Sep 23, 2022
Besu VM vulnerable to gas allocation error in CALL operations
Critical
CVE-2022-36025
was published
for
org.hyperledger.besu:evm
(Maven)
Sep 23, 2022
Rancher API and cluster.management.cattle.io object vulnerable to plaintext storage and exposure of credentials
Critical
CVE-2021-36782
was published
for
github.com/rancher/rancher
(Go)
Sep 23, 2022
Keycloak vulnerable to Stored Cross site Scripting (XSS) when loading default roles
Moderate
CVE-2022-2256
was published
for
org.keycloak:keycloak-parent
(Maven)
Sep 23, 2022
Keycloak SAML javascript protocol mapper: Uploading of scripts through admin console
High
CVE-2022-2668
was published
for
org.keycloak:keycloak-parent
(Maven)
Sep 23, 2022
lakeFS vulnerable to authenticated users deleting files they are not authorized to delete
High
GHSA-28q9-9c3g-v3f9
was published
for
github.com/treeverse/lakefs
(Go)
Sep 23, 2022
Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP
High
CVE-2022-40705
was published
for
soap:soap
(Maven)
Sep 23, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS via Tag Name
Moderate
CVE-2022-28982
was published
for
com.liferay:com.liferay.asset.taglib
(Maven)
Sep 23, 2022
Liferay Portal and Liferay DXP Fails to Check Permissions in Translation Module
Moderate
CVE-2022-38512
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 23, 2022
Liferay Portal and Liferay DXP HtmlUtil.escapeRedirect Can Be Circumvented
Moderate
CVE-2022-28977
was published
for
com.liferay.portal:com.liferay.util.java
(Maven)
Sep 23, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS via the filter_ Prefix
Moderate
CVE-2022-28980
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 23, 2022
Liferay Portal Missing Authorization vulnerability
Moderate
CVE-2022-39975
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Sep 23, 2022
HashiCorp Vault vulnerable to incorrect metadata access
Critical
CVE-2022-40186
was published
for
github.com/hashicorp/vault
(Go)
Sep 23, 2022
Liferay Portal and Liferay DXP Vulnerable to XSS in the Portal Search Module
Moderate
CVE-2022-28979
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Sep 23, 2022
ProTip!
Advisories are also available from the
GraphQL API