GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,775 advisories
Filter by severity
OpenSearch has issue with fine-grained access control of indices backing data streams
Moderate
CVE-2022-41918
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Mar 7, 2023
Apache HTTP Server via mod_proxy_uwsgi HTTP response smuggling
High
CVE-2023-27522
was published
for
uWSGI
(pip)
Mar 7, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24775
was published
for
funadmin/funadmin
(Composer)
Mar 7, 2023
OpenSearch has time discrepancy in authentication responses
Moderate
CVE-2023-25806
was published
for
org.opensearch.plugin:opensearch-security
(Maven)
Mar 7, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24781
was published
for
funadmin/funadmin
(Composer)
Mar 7, 2023
Withdrawn Advisory: Pimcore vulnerable to Cross-site Scripting
Moderate
CVE-2023-1247
was published
for
pimcore/pimcore
(Composer)
Mar 7, 2023
•
withdrawn
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1243
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1242
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1240
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1237
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1241
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1238
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1239
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1245
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1244
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2021-36398
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2021-36399
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle has Incorrect Default Permissions
Moderate
CVE-2021-36397
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle vulnerable to Stored Cross-site Scripting
Moderate
CVE-2021-36401
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
openstack-neutron uncontrolled resource consumption flaw
Moderate
CVE-2022-3277
was published
for
neutron
(pip)
Mar 7, 2023
Moodle has Incorrect Default Permissions
Moderate
CVE-2021-36400
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle has a Hidden Functionality vulnerability
Moderate
CVE-2021-36403
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle Improper Input Validation vulnerability
Moderate
CVE-2021-36402
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Insufficient Session Expiration in pretix
High
CVE-2023-27891
was published
for
pretix
(pip)
Mar 7, 2023
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
Low
CVE-2022-4134
was published
for
glance
(pip)
Mar 7, 2023
ProTip!
Advisories are also available from the
GraphQL API