GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,331
Erlang
31
GitHub Actions
21
Go
2,093
Maven
5,000+
npm
3,756
NuGet
678
pip
3,443
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
9,221 advisories
Filter by severity
Cross site scripting in Silverpeas Core
Moderate
CVE-2024-56923
was published
for
org.silverpeas.core:silverpeas-core
(Maven)
Jan 22, 2025
Missing permission checks in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24403
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
CSRF vulnerability in Jenkins Azure Service Fabric Plugin
Moderate
CVE-2025-24402
was published
for
org.jenkins-ci.plugins:service-fabric
(Maven)
Jan 22, 2025
Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin
Moderate
CVE-2025-24401
was published
for
io.jenkins.plugins:folder-auth
(Maven)
Jan 22, 2025
Cache confusion in Jenkins Eiffel Broadcaster Plugin
Moderate
CVE-2025-24400
was published
for
com.axis.jenkins.plugins.eiffel:eiffel-broadcaster
(Maven)
Jan 22, 2025
Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs
Moderate
CVE-2025-24397
was published
for
org.jenkins-ci.plugins:gitlab-plugin
(Maven)
Jan 22, 2025
aiosmtpd vulnerable to SMTP smuggling
Moderate
CVE-2024-27305
was published
for
aiosmtpd
(pip)
Mar 13, 2024
Onnx Out-of-bounds Read vulnerability
Moderate
CVE-2024-27319
was published
for
onnx
(pip)
Feb 23, 2024
Cilium has an information leakage via insecure default Hubble UI CORS header
Moderate
CVE-2025-23047
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
DoS in Cilium agent DNS proxy from crafted DNS responses
Moderate
CVE-2025-23028
was published
for
github.com/cilium/cilium
(Go)
Jan 22, 2025
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Moderate
CVE-2025-0604
was published
for
org.keycloak:keycloak-ldap-federation
(Maven)
Jan 22, 2025
ps_contactinfo has a potential XSS due to usage of the nofilter tag in template
Moderate
CVE-2025-24027
was published
for
prestashop/ps_contactinfo
(Composer)
Jan 22, 2025
matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
Moderate
CVE-2024-52813
was published
for
matrix-sdk-crypto
(Rust)
Jan 7, 2025
Action Pack contains database-query restrictions bypass
Moderate
CVE-2012-2660
was published
for
actionpack
(RubyGems)
Oct 24, 2017
actionpack Improper Authentication vulnerability
Moderate
CVE-2012-3424
was published
for
actionpack
(RubyGems)
Oct 24, 2017
Use of Insufficiently Random Values in undici
Moderate
CVE-2025-22150
was published
for
undici
(npm)
Jan 21, 2025
Webtrees Path Traversal vulnerability
Moderate
CVE-2024-22723
was published
for
fisharebest/webtrees
(Composer)
Feb 28, 2024
Submariner Operator sets unnecessary RBAC permissions
Moderate
CVE-2024-5042
was published
for
github.com/submariner-io/submariner-operator
(Go)
May 17, 2024
XSS/HTML Injection Vulnerability in Umbraco Preview Badge
Moderate
GHSA-69cg-w8vm-h229
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
Umbraco Allows User Enumeration Feasible Based On Management API Timing and Response Codes
Moderate
CVE-2025-24011
was published
for
Umbraco.Cms
(NuGet)
Jan 21, 2025
MathLive's Lack of Escaping of HTML allows for XSS
Moderate
GHSA-qwj6-q94f-8425
was published
for
mathlive
(npm)
Jan 21, 2025
Missing validation of header name and value in codeigniter4/framework
Moderate
CVE-2025-24013
was published
for
codeigniter4/framework
(Composer)
Jan 21, 2025
gix-worktree-state nonexclusive checkout sets executable files world-writable
Moderate
CVE-2025-22620
was published
for
gix-worktree-state
(Rust)
Jan 21, 2025
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Moderate
CVE-2025-22131
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 21, 2025
Excessive Platform Resource Consumption within a Loop when unmarshalling Compose file having recursive loop
Moderate
CVE-2024-10846
was published
for
github.com/compose-spec/compose-go/v2
(Go)
Jan 21, 2025
ProTip!
Advisories are also available from the
GraphQL API