GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            24,487 advisories
        Filter by severity
        
      
      
    
                    
                      wifey vulnerable to Command Injection due to improper input sanitization
                    
                      
  Critical
                    
                
                      
                        CVE-2022-25890
                      
                      was published
                        for
                        
                          wifey
                        
                        (npm)
                      Jan 9, 2023 
                    
                  
                    
                      Barzahlen Payment Module PHP SDK vulnerable to Observable Timing Discrepancy
                    
                      
  Moderate
                    
                
                      
                        CVE-2016-15015
                      
                      was published
                        for
                        
                          barzahlen/barzahlen-php
                        
                        (Composer)
                      Jan 8, 2023 
                    
                  
                    
                      SUKOHI Surpass Path Traversal vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2015-10030
                      
                      was published
                        for
                        
                          sukohi/surpass
                        
                        (Composer)
                      Jan 8, 2023 
                    
                  
                    
                      WebPA SQL Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2021-4308
                      
                      was published
                        for
                        
                          webpa/webpa
                        
                        (Composer)
                      Jan 8, 2023 
                    
                  
                    
                      PaginationServiceProvider SQL Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2014-125029
                      
                      was published
                        for
                        
                          ttskch/pagination-service-provider
                        
                        (Composer)
                      Jan 8, 2023 
                    
                  
                    
                      Squalor SQL Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2020-36645
                      
                      was published
                        for
                        
                          github.com/square/squalor
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      gosqljson SQL Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2014-125064
                      
                      was published
                        for
                        
                          github.com/elgs/gosqljson
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      kelvinmo simplexrd vulnerable to Improper Restriction of XML External Entity Reference
                    
                      
  Critical
                    
                
                      
                        CVE-2015-10029
                      
                      was published
                        for
                        
                          kelvinmo/simplexrd
                        
                        (Composer)
                      Jan 7, 2023 
                    
                  
                    
                      Baobab vulnerable to Prototype Pollution
                    
                      
  Critical
                    
                
                      
                        CVE-2021-4307
                      
                      was published
                        for
                        
                          baobab
                        
                        (npm)
                      Jan 7, 2023 
                    
                  
                    
                      Symbiote Seed Open Redirect vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2017-20164
                      
                      was published
                        for
                        
                          symbiote/silverstripe-seed
                        
                        (Composer)
                      Jan 7, 2023 
                    
                  
                    
                      terminal-kit Inefficient Regular Expression Complexity vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2021-4306
                      
                      was published
                        for
                        
                          terminal-kit
                        
                        (npm)
                      Jan 7, 2023 
                    
                  
                    
                      Inline SVG vulnerable to Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-36644
                      
                      was published
                        for
                        
                          inline_svg
                        
                        (RubyGems)
                      Jan 7, 2023 
                    
                  
                    
                      easy-scrypt Observable Timing Discrepancy vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2014-125055
                      
                      was published
                        for
                        
                          github.com/agnivade/easy-scrypt
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0107
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0106
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0108
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0111
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0112
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      usememos/memos vulnerable to stored Cross-site Scripting
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-0110
                      
                      was published
                        for
                        
                          github.com/usememos/memos
                        
                        (Go)
                      Jan 7, 2023 
                    
                  
                    
                      Tokio reject_remote_clients configuration may get dropped when creating a Windows named pipe
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-22466
                      
                      was published
                        for
                        
                          tokio
                        
                        (Rust)
                      Jan 6, 2023 
                    
                  
                    
                      globalpom-utils has Insecure Temporary File
                    
                      
  Critical
                    
                
                      
                        CVE-2018-25068
                      
                      was published
                        for
                        
                          com.anrisoftware.globalpom:globalpomutils
                        
                        (Maven)
                      Jan 6, 2023 
                    
                  
                    
                      Http4s improperly parses User-Agent and Server headers
                    
                      
  High
                    
                
                      
                        CVE-2023-22465
                      
                      was published
                        for
                        
                          org.http4s:http4s-core
                        
                        (Maven)
                      Jan 6, 2023 
                    
                  
                    
                      himiklab yii2-jqgrid-widget vulnerable to SQL Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2014-125051
                      
                      was published
                        for
                        
                          himiklab/yii2-jqgrid-widget
                        
                        (Composer)
                      Jan 6, 2023 
                    
                  
                    
                      KubePi allows malicious actor to login with a forged JWT token via Hardcoded Jwtsigkeys
                    
                      
  Critical
                    
                
                      
                        CVE-2023-22463
                      
                      was published
                        for
                        
                          github.com/KubeOperator/kubepi
                        
                        (Go)
                      Jan 6, 2023 
                    
                  
                    
                      XWiki CKEditor.HTMLConverter vulnerable to Remote Code Execution via Cross-Site Request Forgery
                    
                      
  Critical
                    
                
                      
                        CVE-2023-22457
                      
                      was published
                        for
                        
                          org.xwiki.contrib:application-ckeditor-ui
                        
                        (Maven)
                      Jan 6, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API