GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,231
Erlang
31
GitHub Actions
20
Go
1,991
Maven
5,000+
npm
3,709
NuGet
661
pip
3,341
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
422 advisories
Filter by severity
Browsershot does not validate URL protocols passed to Browsershot URL method
High
CVE-2022-41706
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
Cross-site Scripting in Apache Hama
High
CVE-2022-45470
was published
for
org.apache.hama:hama-core
(Maven)
Nov 21, 2022
Witness Block Parsing DoS Vulnerability
High
CVE-2022-39389
was published
for
github.com/lightningnetwork/lnd
(Go)
Nov 18, 2022
Apache Tomcat may reject request containing invalid Content-Length header
High
CVE-2022-42252
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Nov 1, 2022
Magento Improper input validation vulnerability
High
CVE-2022-42344
was published
for
magento/community-edition
(Composer)
Oct 20, 2022
parse-server crashes when receiving file download request with invalid byte range
High
CVE-2022-39313
was published
for
parse-server
(npm)
Oct 18, 2022
Remote denial of service in Hyperledger Fabric Gateway
High
CVE-2022-36023
was published
for
github.com/hyperledger/fabric
(Go)
Oct 13, 2022
Cloudflare GoFlow vulnerable to a Denial of Service in the sflow packet handling package
High
CVE-2022-2529
was published
for
github.com/cloudflare/goflow/v3
(Go)
Oct 1, 2022
Hyperledger Fabric subject to Denial of Service via non-validated request
High
CVE-2022-35253
was published
for
github.com/hyperledger/fabric
(Go)
Sep 25, 2022
WASM3 Improper Input Validation vulnerability
High
CVE-2022-39974
was published
for
pywasm3
(pip)
Sep 21, 2022
OPA Compiler: Bypass of WithUnsafeBuiltins using "with" keyword to mock functions
High
CVE-2022-36085
was published
for
github.com/open-policy-agent/opa
(Go)
Sep 16, 2022
elrond-go MultiESDTNFTTransfer call on a SC address with missing function name
High
CVE-2022-36058
was published
for
github.com/ElrondNetwork/elrond-go
(Go)
Sep 1, 2022
Improper token validation leading to code execution in Teleport
High
CVE-2022-36633
was published
for
github.com/gravitational/teleport
(Go)
Aug 25, 2022
ansible-runner vulnerable to shell command injection
High
CVE-2021-4041
was published
for
ansible-runner
(pip)
Aug 25, 2022
django-sendfile2 before 0.7.0 contains reflected file download vulnerability
High
GHSA-pcjh-6r5h-r92r
was published
for
django-sendfile2
(pip)
Aug 11, 2022
Apache Avro Rust SDK corrupted data read can cause crash
High
CVE-2022-36125
was published
for
apache-avro
(Rust)
Aug 10, 2022
Moodle Arbitrary file read when importing lesson questions
High
CVE-2022-35650
was published
for
moodle/moodle
(Composer)
Jul 26, 2022
OpenZeppelin Contracts's SignatureChecker may revert on invalid EIP-1271 signers
High
CVE-2022-31172
was published
for
@openzeppelin/contracts
(npm)
Jul 21, 2022
OpenZeppelin Contracts's ERC165Checker may revert instead of returning false
High
CVE-2022-31170
was published
for
@openzeppelin/contracts
(npm)
Jul 21, 2022
aws-iam-authenticator allow-listed IAM identity may be able to modify their username, escalate privileges before v0.5.9
High
CVE-2022-2385
was published
for
sigs.k8s.io/aws-iam-authenticator
(Go)
Jul 13, 2022
Hyperledger Fabric vulnerable to Improper Input Validation in orderer/common/cluster consensus request
High
CVE-2022-31121
was published
for
github.com/hyperledger/fabric
(Go)
Jul 8, 2022
Improper Input Validation in RESTEasy
High
CVE-2020-1695
was published
for
org.jboss.resteasy:resteasy-client
(Maven)
May 24, 2022
bson-objectid contains Improper input validation
High
CVE-2019-19729
was published
for
bson-objectid
(npm)
May 24, 2022
TYPO3 Image Processing susceptible to Code Execution
High
CVE-2019-11832
was published
for
typo3/cms
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API