GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
1,081
Erlang
18
GitHub Actions
4
Go
641
Maven
2,207
npm
2,716
NuGet
228
pip
1,397
Pub
3
RubyGems
519
Rust
531
Unreviewed advisories
All unreviewed
5,000+
9,291 advisories
Filter by severity
Origin Validation Error in rdiffweb
Critical
CVE-2022-3457
was published
for
rdiffweb
(pip)
Oct 14, 2022
Remote denial of service in Hyperledger Fabric Gateway
High
CVE-2022-36023
was published
for
github.com/hyperledger/fabric
(Go)
Oct 13, 2022
October CMS Safe Mode bypass leads to authenticated Remote Code Execution
Moderate
CVE-2022-35944
was published
for
october/system
(Composer)
Oct 13, 2022
Powerline Gitstatus vulnerable to arbitrary code execution
High
CVE-2022-42906
was published
for
powerline-gitstatus
(pip)
Oct 13, 2022
Signature bypass via multiple root elements
High
CVE-2022-39300
was published
for
node-saml
(npm)
Oct 12, 2022
Signature bypass via multiple root elements
High
CVE-2022-39299
was published
for
@node-saml/node-saml
(npm)
Oct 12, 2022
com.enonic.xp:lib-auth vulnerable to Session Fixation
Critical
GHSA-4m5p-5w5w-3jcf
was published
for
com.enonic.xp:lib-auth
(Maven)
Oct 12, 2022
Dolibarr vulnerable to Eval Injection
High
CVE-2022-40871
was published
for
dolibarr/dolibarr
(Composer)
Oct 12, 2022
com.amazon.redshift:redshift-jdbc42 vulnerable to remote command execution
High
CVE-2022-41828
was published
for
com.amazon.redshift:redshift-jdbc42
(Maven)
Oct 12, 2022
The graphql-upload library included in Apollo Server 2 is vulnerable to CSRF mutations
Moderate
GHSA-2p3c-p3qw-69r4
was published
for
apollo-server
(npm)
Oct 12, 2022
Nomad Panics On Job Submission With Bad Artifact Stanza Source URL
Moderate
CVE-2022-41606
was published
for
github.com/hashicorp/nomad
(Go)
Oct 12, 2022
Apache Shiro Authentication Bypass vulnerability
Critical
CVE-2022-40664
was published
for
org.apache.shiro:shiro-core
(Maven)
Oct 12, 2022
NuGet Elevation of Privilege Vulnerability
High
CVE-2022-41032
was published
for
NuGet.CommandLine
(NuGet)
Oct 11, 2022
melisplatform/melis-asset-manager vulnerable to Path Traversal
High
CVE-2022-39296
was published
for
melisplatform/melis-asset-manager
(Composer)
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
High
CVE-2022-39297
was published
for
melisplatform/melis-cms
(Composer)
Oct 11, 2022
melisplatform/melis-front vulnerable to deserialization of untrusted data
High
CVE-2022-39298
was published
for
melisplatform/melis-front
(Composer)
Oct 11, 2022
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom
Moderate
CVE-2022-37616
was published
for
@xmldom/xmldom
(npm)
Oct 11, 2022
Poetry vulnerable to Untrusted Search Path leading to Local Code Execution on Windows
High
CVE-2022-36070
was published
for
poetry
(pip)
Oct 11, 2022
django-mfa2 vulnerable to MFA Replay attack
High
CVE-2022-42731
was published
for
django-mfa2
(pip)
Oct 11, 2022
AdGuardHome vulnerable to Cross-Site Request Forgery
Moderate
CVE-2022-32175
was published
for
github.com/AdguardTeam/AdGuardHome
(Go)
Oct 11, 2022
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
High
CVE-2022-3358
was published
for
openssl-src
(Rust)
Oct 11, 2022
Gogs vulnerable to Cross-site Scripting
Critical
CVE-2022-32174
was published
for
gogs.io/gogs
(Go)
Oct 11, 2022
Cross site scripting in Metro UI
Moderate
CVE-2022-41376
was published
for
metro4
(npm)
Oct 11, 2022
fastify vulnerable to denial of service via malicious Content-Type
High
CVE-2022-39288
was published
for
fastify
(npm)
Oct 11, 2022
Traefik HTTP/2 connections management could cause a denial of service
High
CVE-2022-39271
was published
for
github.com/traefik/traefik/v2
(Go)
Oct 10, 2022
ProTip!
Advisories are also available from the
GraphQL API

