GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,692
Erlang
34
GitHub Actions
27
Go
2,279
Maven
5,000+
npm
3,931
NuGet
708
pip
3,699
Pub
12
RubyGems
919
Rust
957
Swift
38
Unreviewed advisories
All unreviewed
5,000+
22,527 advisories
Filter by severity
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password
Moderate
CVE-2022-2368
was published
for
microweber/microweber
(Composer)
Jul 12, 2022
SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely
Critical
CVE-2022-31506
was published
for
opendiamond
(pip)
Jul 12, 2022
DoS in KubeEdge's Websocket Client in package Viaduct
Moderate
CVE-2022-31080
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge Cloud Stream and Edge Stream DoS from large stream message
Moderate
CVE-2022-31079
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge CloudCore Router memory exhaustion vulnerability
Moderate
CVE-2022-31078
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge DoS when signing the CSR from EdgeCore
Moderate
CVE-2022-31075
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge Cloud AdmissionController component DoS
Moderate
CVE-2022-31074
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
KubeEdge Edge ServiceBus module DoS
Moderate
CVE-2022-31073
was published
for
github.com/kubeedge/kubeedge
(Go)
Jul 11, 2022
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot
High
CVE-2022-27772
was published
for
org.springframework.boot:spring-boot
(Maven)
Jul 11, 2022
Microweber before v1.2.20 vulnerable to cross-site scripting
Moderate
CVE-2022-2353
was published
for
microweber/microweber
(Composer)
Jul 10, 2022
Known vulnerable to account takeover via host header injection attack in v1.3.1
High
CVE-2022-33011
was published
for
idno/known
(Composer)
Jul 9, 2022
Known vulnerable to code execution via SVG file in v1.3.1
Moderate
CVE-2022-32115
was published
for
idno/known
(Composer)
Jul 9, 2022
Known v1.3.1 Cross-site Scripting
Moderate
CVE-2022-31290
was published
for
idno/known
(Composer)
Jul 9, 2022
Known v1.3.1 contains Insecure Direct Object Reference
Moderate
CVE-2022-30852
was published
for
idno/known
(Composer)
Jul 9, 2022
rpc.py vulnerable to Deserialization of Untrusted Data
Critical
CVE-2022-35411
was published
for
rpc.py
(pip)
Jul 9, 2022
Hyperledger Fabric vulnerable to Improper Input Validation in orderer/common/cluster consensus request
High
CVE-2022-31121
was published
for
github.com/hyperledger/fabric
(Go)
Jul 8, 2022
Insecure cookies in Openshift Origin
Moderate
CVE-2015-3207
was published
for
github.com/openshift/origin
(Go)
Jul 8, 2022
Apache Druid before 0.23.0 vulnerable to clickjacking
Moderate
CVE-2022-28889
was published
for
org.apache.druid:druid
(Maven)
Jul 8, 2022
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification
Moderate
CVE-2015-5298
was published
for
org.jenkins-ci.plugins:google-login
(Maven)
Jul 8, 2022
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters
Moderate
CVE-2021-44791
was published
for
org.apache.druid:druid
(Maven)
Jul 8, 2022
Snipe-IT 6.0.2 vulnerable to Cross-site Scripting via arbitrary file upload in Update Branding Settings
Moderate
CVE-2022-32060
was published
for
snipe/snipe-it
(Composer)
Jul 8, 2022
XML External Entity Reference in Eclipse Lyo
Moderate
CVE-2021-41042
was published
for
org.eclipse.lyo:lyo-parent
(Maven)
Jul 8, 2022
Snipe-IT 6.0.2 vulnerable to Cross-site Scripting
Moderate
CVE-2022-32061
was published
for
snipe/snipe-it
(Composer)
Jul 8, 2022
Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service
High
CVE-2022-2048
was published
for
org.eclipse.jetty.http2:http2-server
(Maven)
Jul 7, 2022
Jetty SslConnection does not release pooled ByteBuffers in case of errors
High
CVE-2022-2191
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Jul 7, 2022
ProTip!
Advisories are also available from the
GraphQL API