GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,508
Erlang
33
GitHub Actions
25
Go
2,213
Maven
5,000+
npm
3,871
NuGet
696
pip
3,643
Pub
12
RubyGems
913
Rust
922
Swift
38
Unreviewed advisories
All unreviewed
5,000+
287 advisories
Filter by severity
OpenNMS vulnerable to remote code execution
High
CVE-2023-40313
was published
for
org.opennms:opennms-base-assembly
(Maven)
Aug 17, 2023
Apache NiFi Code Injection vulnerability
High
CVE-2023-36542
was published
for
org.apache.nifi:nifi-cdc-mysql-bundle
(Maven)
Jul 29, 2023
SwiftTerm Code Injection vulnerability
High
CVE-2022-23465
was published
for
github.com/migueldeicaza/SwiftTerm
(Swift)
Jul 14, 2023
Backstage Scaffolder plugin has insecure sandbox
High
CVE-2023-35926
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Jun 21, 2023
Grav Server-side Template Injection (SSTI) via Denylist Bypass Vulnerability
High
CVE-2023-34253
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Grav Server-side Template Injection (SSTI) via Twig Default Filters
High
CVE-2023-34252
was published
for
getgrav/grav
(Composer)
Jun 16, 2023
Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability
High
CVE-2023-30179
was published
for
craftcms/cms
(Composer)
Jun 13, 2023
•
withdrawn
Apache NiFi vulnerable to Code Injection
High
CVE-2023-34468
was published
for
org.apache.nifi:nifi-dbcp-base
(Maven)
Jun 12, 2023
Reportlab vulnerable to remote code execution
High
CVE-2023-33733
was published
for
reportlab
(pip)
Jun 5, 2023
Code injection in nilsteampassnet/teampass
High
CVE-2023-2859
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2023
Sqlite-jdbc vulnerable to remote code execution when JDBC url is attacker controlled
High
CVE-2023-32697
was published
for
org.xerial:sqlite-jdbc
(Maven)
May 23, 2023
CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
High
CVE-2023-30130
was published
for
craftcms/cms
(Composer)
May 12, 2023
teampass vulnerable to code injection
High
CVE-2023-2591
was published
for
nilsteampassnet/teampass
(Composer)
May 9, 2023
Improper Control of Generation of Code in Twig rendered views
High
CVE-2023-2017
was published
for
shopware/core
(Composer)
Apr 18, 2023
Code Injection in alextselegidis/easyappointments
High
CVE-2023-1367
was published
for
alextselegidis/easyappointments
(Composer)
Mar 13, 2023
SketchSVG Arbitrary Code Injection vulnerability
High
CVE-2023-26107
was published
for
sketchsvg
(npm)
Mar 6, 2023
Nautobot vulnerable to remote code execution via Jinja2 template rendering
High
CVE-2023-25657
was published
for
nautobot
(pip)
Feb 22, 2023
Code Injection in froxlor/froxlor
High
CVE-2023-0877
was published
for
froxlor/froxlor
(Composer)
Feb 17, 2023
froxlor is vulnerable to privilege escalation from customer to root via directory-options
High
CVE-2023-0671
was published
for
froxlor/froxlor
(Composer)
Feb 4, 2023
Eta vulnerable to Code Injection via templates rendered with user-defined data
High
CVE-2022-25967
was published
for
eta
(npm)
Jan 30, 2023
NYUCCL psiTurk IS vulnerable to Improper Neutralization of Special Elements
High
CVE-2021-4315
was published
for
psiTurk
(pip)
Jan 29, 2023
Command injection in yiisoft/yii2-gii
High
CVE-2020-36655
was published
for
yiisoft/yii2-gii
(Composer)
Jan 21, 2023
ruby-git has potential remote code execution vulnerability
High
CVE-2022-46648
was published
for
git
(RubyGems)
Jan 9, 2023
ProTip!
Advisories are also available from the
GraphQL API