Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

22,527 advisories

Loading
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password Moderate
CVE-2022-2368 was published for microweber/microweber (Composer) Jul 12, 2022
SatyaLab opendiamond 10.1.1 vulnerable to path traversal because Flask send_file function used unsafely Critical
CVE-2022-31506 was published for opendiamond (pip) Jul 12, 2022
DoS in KubeEdge's Websocket Client in package Viaduct Moderate
CVE-2022-31080 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
DavidKorczynski AdamKorcz
KubeEdge Cloud Stream and Edge Stream DoS from large stream message Moderate
CVE-2022-31079 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
AdamKorcz DavidKorczynski
KubeEdge CloudCore Router memory exhaustion vulnerability Moderate
CVE-2022-31078 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
DavidKorczynski AdamKorcz
KubeEdge DoS when signing the CSR from EdgeCore Moderate
CVE-2022-31075 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
DavidKorczynski AdamKorcz
KubeEdge Cloud AdmissionController component DoS Moderate
CVE-2022-31074 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
DavidKorczynski AdamKorcz
KubeEdge Edge ServiceBus module DoS Moderate
CVE-2022-31073 was published for github.com/kubeedge/kubeedge (Go) Jul 11, 2022
DavidKorczynski AdamKorcz
Temporary Directory Hijacking to Local Privilege Escalation Vulnerability in org.springframework.boot:spring-boot High
CVE-2022-27772 was published for org.springframework.boot:spring-boot (Maven) Jul 11, 2022
trgpa JLLeitschuh
Microweber before v1.2.20 vulnerable to cross-site scripting Moderate
CVE-2022-2353 was published for microweber/microweber (Composer) Jul 10, 2022
Known vulnerable to account takeover via host header injection attack in v1.3.1 High
CVE-2022-33011 was published for idno/known (Composer) Jul 9, 2022
Known vulnerable to code execution via SVG file in v1.3.1 Moderate
CVE-2022-32115 was published for idno/known (Composer) Jul 9, 2022
Known v1.3.1 Cross-site Scripting Moderate
CVE-2022-31290 was published for idno/known (Composer) Jul 9, 2022
Known v1.3.1 contains Insecure Direct Object Reference Moderate
CVE-2022-30852 was published for idno/known (Composer) Jul 9, 2022
rpc.py vulnerable to Deserialization of Untrusted Data Critical
CVE-2022-35411 was published for rpc.py (pip) Jul 9, 2022
Hyperledger Fabric vulnerable to Improper Input Validation in orderer/common/cluster consensus request High
CVE-2022-31121 was published for github.com/hyperledger/fabric (Go) Jul 8, 2022
fatal0
Insecure cookies in Openshift Origin Moderate
CVE-2015-3207 was published for github.com/openshift/origin (Go) Jul 8, 2022
Apache Druid before 0.23.0 vulnerable to clickjacking Moderate
CVE-2022-28889 was published for org.apache.druid:druid (Maven) Jul 8, 2022
Jenkins Google Login Plugin 1.0 and 1.1 allows anonymous users to authenticate through client-side request modification Moderate
CVE-2015-5298 was published for org.jenkins-ci.plugins:google-login (Maven) Jul 8, 2022
Apache Druid before 0.23.0 vulnerable to reflected XSS via unescaped URL parameters Moderate
CVE-2021-44791 was published for org.apache.druid:druid (Maven) Jul 8, 2022
Snipe-IT 6.0.2 vulnerable to Cross-site Scripting via arbitrary file upload in Update Branding Settings Moderate
CVE-2022-32060 was published for snipe/snipe-it (Composer) Jul 8, 2022
XML External Entity Reference in Eclipse Lyo Moderate
CVE-2021-41042 was published for org.eclipse.lyo:lyo-parent (Maven) Jul 8, 2022
Snipe-IT 6.0.2 vulnerable to Cross-site Scripting Moderate
CVE-2022-32061 was published for snipe/snipe-it (Composer) Jul 8, 2022
Jetty vulnerable to Invalid HTTP/2 requests that can lead to denial of service High
CVE-2022-2048 was published for org.eclipse.jetty.http2:http2-server (Maven) Jul 7, 2022
bjorncs hakonhall
Jetty SslConnection does not release pooled ByteBuffers in case of errors High
CVE-2022-2191 was published for org.eclipse.jetty:jetty-server (Maven) Jul 7, 2022
ProTip! Advisories are also available from the GraphQL API