Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

122,221 advisories

Loading
open-webui allows writing and deleting arbitrary files Moderate
CVE-2024-7037 was published for open-webui (pip) Oct 9, 2024
Grafana Alloy on Windows has Unquoted Search Path or Element vulnerability Moderate
CVE-2024-8975 was published for github.com/grafana/alloy (Go) Sep 25, 2024
Plone Cross-site scripting Vulnerability Moderate
CVE-2012-5502 was published for Plone (pip) May 17, 2022
Plone Cross-site scripting Vulnerability Moderate
CVE-2012-5504 was published for Plone (pip) May 17, 2022
Plone Cross-site scripting Vulnerability Moderate
CVE-2012-5494 was published for Plone (pip) May 17, 2022
Plone Sandbox Bypass Moderate
CVE-2012-5493 was published for Plone (pip) May 17, 2022
Plone Cross-site scripting Vulnerability Moderate
CVE-2012-5490 was published for Plone (pip) May 17, 2022
Plone Metadata Disclosure Moderate
CVE-2012-5492 was published for Plone (pip) May 17, 2022
pip lack of randomness in build directory Moderate
CVE-2014-8991 was published for pip (pip) May 13, 2022
plone.rest vulnerable to Denial of Service when ++api++ is used many times Moderate
CVE-2023-42457 was published for plone.rest (pip) Sep 21, 2023
Regular Expression Denial of Service (ReDoS) in Pillow Moderate
CVE-2021-25292 was published for Pillow (pip) Mar 29, 2021
sunSUNQ
Deserialization of Untrusted Data in parlai Moderate
CVE-2021-39207 was published for parlai (pip) Sep 13, 2021
Anon-Artist
Paste is vulnerable to Cross-site Scripting via vectors involving a 404 status code Moderate
CVE-2010-2477 was published for paste (pip) May 17, 2022
Cross-site scripting in papermerge Moderate
CVE-2020-29456 was published for papermerge (pip) Apr 20, 2021
Pillow Temporary file name leakage Moderate
CVE-2014-1933 was published for Pillow (pip) May 18, 2020
Exposure of Sensitive Information in OPC UA .NET Standard Reference Server Moderate
CVE-2023-31048 was published for OPCFoundation.NetStandard.Opc.Ua.Core (NuGet) May 5, 2023
Pillow Buffer overflow in ImagingLibTiffDecode Moderate
CVE-2016-0740 was published for pillow (pip) Jul 24, 2018
Jenkins Gogs Plugin vulnerable to unsafe default behavior and information disclosure Moderate
CVE-2023-40348 was published for org.jenkins-ci.plugins:gogs-webhook (Maven) Aug 16, 2023
wasmtime has a runtime crash when combining tail calls with trapping imports Moderate
CVE-2024-47763 was published for wasmtime (Rust) Oct 9, 2024
alexcrichton fitzgen
ProTip! Advisories are also available from the GraphQL API