GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
122,221 advisories
Filter by severity
open-webui allows writing and deleting arbitrary files
Moderate
CVE-2024-7037
was published
for
open-webui
(pip)
Oct 9, 2024
Grafana Alloy on Windows has Unquoted Search Path or Element vulnerability
Moderate
CVE-2024-8975
was published
for
github.com/grafana/alloy
(Go)
Sep 25, 2024
Plone Cross-site scripting Vulnerability
Moderate
CVE-2012-5502
was published
for
Plone
(pip)
May 17, 2022
Plone Cross-site scripting Vulnerability
Moderate
CVE-2012-5504
was published
for
Plone
(pip)
May 17, 2022
Plone Cross-site scripting Vulnerability
Moderate
CVE-2012-5494
was published
for
Plone
(pip)
May 17, 2022
Plone Cross-site scripting Vulnerability
Moderate
CVE-2012-5490
was published
for
Plone
(pip)
May 17, 2022
VMware NSX contains a local privilege escalation vulnerability.
An authenticated malicious...
Moderate
Unreviewed
CVE-2024-38818
was published
Oct 9, 2024
VMware NSX contains a content spoofing vulnerability.
An unauthenticated malicious actor may be...
Moderate
Unreviewed
CVE-2024-38815
was published
Oct 9, 2024
Mware NSX contains a command injection vulnerability.
A malicious actor with access to the NSX...
Moderate
Unreviewed
CVE-2024-38817
was published
Oct 9, 2024
pip lack of randomness in build directory
Moderate
CVE-2014-8991
was published
for
pip
(pip)
May 13, 2022
plone.rest vulnerable to Denial of Service when ++api++ is used many times
Moderate
CVE-2023-42457
was published
for
plone.rest
(pip)
Sep 21, 2023
Regular Expression Denial of Service (ReDoS) in Pillow
Moderate
CVE-2021-25292
was published
for
Pillow
(pip)
Mar 29, 2021
Deserialization of Untrusted Data in parlai
Moderate
CVE-2021-39207
was published
for
parlai
(pip)
Sep 13, 2021
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code
Moderate
CVE-2010-2477
was published
for
paste
(pip)
May 17, 2022
Cross-site scripting in papermerge
Moderate
CVE-2020-29456
was published
for
papermerge
(pip)
Apr 20, 2021
Pillow Temporary file name leakage
Moderate
CVE-2014-1933
was published
for
Pillow
(pip)
May 18, 2020
Exposure of Sensitive Information in OPC UA .NET Standard Reference Server
Moderate
CVE-2023-31048
was published
for
OPCFoundation.NetStandard.Opc.Ua.Core
(NuGet)
May 5, 2023
Pillow Buffer overflow in ImagingLibTiffDecode
Moderate
CVE-2016-0740
was published
for
pillow
(pip)
Jul 24, 2018
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure
Moderate
CVE-2023-40348
was published
for
org.jenkins-ci.plugins:gogs-webhook
(Maven)
Aug 16, 2023
wasmtime has a runtime crash when combining tail calls with trapping imports
Moderate
CVE-2024-47763
was published
for
wasmtime
(Rust)
Oct 9, 2024
3DSecure 2.0 allows form action hijacking via threeDsMethod.jsp?threeDSMethodData= or the...
Moderate
Unreviewed
CVE-2024-25285
was published
Oct 9, 2024
In the Linux kernel, the following vulnerability has been resolved:
userfaultfd: don't BUG_ON()...
Moderate
Unreviewed
CVE-2024-46838
was published
Sep 27, 2024
In the process of testing the Relevanssi WordPress plugin before 4.23.1, a vulnerability was...
Moderate
Unreviewed
CVE-2024-9021
was published
Oct 8, 2024
ProTip!
Advisories are also available from the
GraphQL API