GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
42 advisories
Filter by severity
plugin.yaml file allows for duplicate entries in helm
Low
CVE-2020-15187
was published
for
helm.sh/helm
(Go)
May 24, 2021
Xuxueli xxl-job template injection vulnerability
Low
CVE-2024-3366
was published
for
com.xuxueli:xxl-job-core
(Maven)
Apr 6, 2024
TwsCachedXPathAPI in Convertigo through 8.3.4 does not restrict the use of commons-jxpath APIs.
Low
Unreviewed
CVE-2025-43955
was published
Apr 20, 2025
Apereo CAS code injection vulnerability
Low
CVE-2025-3984
was published
for
org.apereo.cas:cas-management-webapp-support
(Maven)
Apr 27, 2025
cookie accepts cookie name, path, and domain with out of bounds characters
Low
CVE-2024-47764
was published
for
cookie
(npm)
Oct 4, 2024
Vulnerability in Wikimedia Foundation MediaWiki, Wikimedia Foundation Parsoid.This issue affects...
Low
Unreviewed
CVE-2025-32699
was published
Apr 10, 2025
CRLF injection vulnerability in the mod_negotiation module in the Apache HTTP Server 2.2.6 and...
Low
Unreviewed
CVE-2008-0456
was published
May 1, 2022
Opera before 8.50 allows remote attackers to spoof the content type of files via a filename with...
Low
Unreviewed
CVE-2005-3007
was published
May 1, 2022
A vulnerability, which was classified as problematic, was found in lmxcms 1.41. Affected is an...
Low
Unreviewed
CVE-2025-1465
was published
Feb 19, 2025
In Shadow 4.13, it is possible to inject control characters into fields provided to the SUID...
Low
Unreviewed
CVE-2023-29383
was published
Apr 15, 2023
A vulnerability was found in TMD Custom Header Menu 4.0.0.1 on OpenCart. It has been rated as...
Low
Unreviewed
CVE-2025-0214
was published
Jan 4, 2025
dbt has an implicit override for built-in materializations from installed packages
Low
CVE-2024-40637
was published
for
dbt-core
(pip)
Jul 17, 2024
RDoc RCE vulnerability with .rdoc_options
Low
CVE-2024-27281
was published
for
rdoc
(RubyGems)
Mar 25, 2024
Langchain SQL Injection vulnerability
Low
CVE-2024-8309
was published
for
langchain
(pip)
Oct 29, 2024
A resource misdirection vulnerability in GitLab CE/EE versions 12.0 prior to 17.0.5, 17.1 prior...
Low
Unreviewed
CVE-2024-0231
was published
Jul 25, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Low
Unreviewed
CVE-2024-35777
was published
Jul 9, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Low
Unreviewed
CVE-2024-37442
was published
Jul 9, 2024
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'...
Low
Unreviewed
CVE-2024-37253
was published
Jul 9, 2024
A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit...
Low
Unreviewed
CVE-2023-6004
was published
Jan 3, 2024
Monolog Header injection in NativeMailerHandler
Low
GHSA-f57v-q966-7fh6
was published
for
monolog/monolog
(Composer)
May 15, 2024
Contao: Unencoded insert tags in the frontend
Low
CVE-2024-28191
was published
for
contao/core-bundle
(Composer)
Apr 9, 2024
PingID integration for Windows login prior to 2.9 does not handle duplicate usernames, which can...
Low
Unreviewed
CVE-2022-23721
was published
Apr 25, 2023
GLPI GLPI Product 9.3.1 is affected by: Frame and Form tags Injection allowing admins to phish...
Low
Unreviewed
CVE-2019-1010310
was published
May 24, 2022
Mattermost Injection vulnerability
Low
CVE-2023-35075
was published
for
github.com/mattermost/mattermost-server/v6
(Go)
Nov 27, 2023
ProTip!
Advisories are also available from the
GraphQL API