GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
284 advisories
Filter by severity
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
Low
CVE-2023-30844
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
PDFZorro PDFZorro Online r20220428 using TCPDF 6.2.5, despite having workflows claiming to...
High
Unreviewed
CVE-2022-30351
was published
Mar 30, 2023
ConEmu through 220807 and Cmder before 1.3.21 report the title of the terminal, including control...
Critical
Unreviewed
CVE-2022-46387
was published
Mar 28, 2023
Cobalt Strike 4.7.1 fails to properly escape HTML tags when they are displayed on Swing...
Critical
Unreviewed
CVE-2022-42948
was published
Mar 24, 2023
Sudo before 1.9.13 does not escape control characters in log messages.
Moderate
Unreviewed
CVE-2023-28486
was published
Mar 16, 2023
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
Moderate
Unreviewed
CVE-2023-28487
was published
Mar 16, 2023
XWiki Platform vulnerable to privilege escalation via async macro and IconThemeSheet from the user profile
Critical
CVE-2023-26472
was published
for
org.xwiki.platform:xwiki-platform-icon-ui
(Maven)
Mar 3, 2023
Keycloak Cross-site Scripting on OpenID connect login service
High
CVE-2022-4137
was published
for
org.keycloak:keycloak-parent
(Maven)
Mar 1, 2023
A CWE-117: Improper Output Neutralization for Logs vulnerability exists that could cause the...
Moderate
Unreviewed
CVE-2023-0595
was published
Feb 24, 2023
An issue was discovered in GNU Emacs through 28.2. htmlfontify.el has a command injection...
Critical
Unreviewed
CVE-2022-48339
was published
Feb 21, 2023
Improper handling of Unicode encoding in source code to be compiled by the Intel(R) C++ Compiler...
Critical
Unreviewed
CVE-2022-25987
was published
Feb 16, 2023
Dell EMC Data Protection Central, versions 19.1 through 19.7, contains a Host Header Injection...
Moderate
Unreviewed
CVE-2022-45102
was published
Feb 1, 2023
A vulnerability was found in gitlearn. It has been declared as problematic. This vulnerability...
Moderate
Unreviewed
CVE-2015-10040
was published
Jan 13, 2023
Apache Tomcat improperly escapes input from JsonErrorReportValve
High
CVE-2022-45143
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Jan 3, 2023
A vulnerability classified as problematic has been found in OpenDNS OpenResolve. This affects an...
Critical
Unreviewed
CVE-2015-10011
was published
Jan 3, 2023
Gin's default logger allows unsanitized input that can allow remote attackers to inject arbitrary log lines
High
CVE-2020-36567
was published
for
github.com/gin-gonic/gin
(Go)
Dec 27, 2022
SVG's <code><use></code> element could have been used to load unexpected content that could...
High
Unreviewed
CVE-2022-28284
was published
Dec 22, 2022
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped...
High
Unreviewed
CVE-2022-22744
was published
Dec 22, 2022
KDDI +Message App, NTT DOCOMO +Message App, and SoftBank +Message App contain a vulnerability...
Moderate
Unreviewed
CVE-2022-43543
was published
Dec 21, 2022
IBM API Connect V10.0.0.0 through V10.0.5.0, V10.0.1.0 through V10.0.1.7, and V2018.4.1.0 through...
Moderate
Unreviewed
CVE-2021-38997
was published
Dec 12, 2022
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header...
High
Unreviewed
CVE-2022-40870
was published
Nov 23, 2022
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') in org.xwiki.platform:xwiki-platform-menu-ui
Critical
CVE-2022-41934
was published
for
org.xwiki.platform:xwiki-platform-menu-ui
(Maven)
Nov 21, 2022
The Five Star Restaurant Reservations WordPress plugin before 2.4.12 does not have authorisation...
Moderate
Unreviewed
CVE-2022-0421
was published
Nov 21, 2022
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue...
Critical
Unreviewed
CVE-2022-4011
was published
Nov 16, 2022
IBM CICS TX 11.1 does not neutralize or incorrectly neutralizes web scripting syntax in HTTP...
Moderate
Unreviewed
CVE-2022-34316
was published
Nov 15, 2022
ProTip!
Advisories are also available from the
GraphQL API