GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
3,417 advisories
Filter by severity
MoinMoin Access Restrictions Bypassed due to improper ACL enforcement
High
CVE-2008-6603
was published
for
moin
(pip)
May 17, 2022
OpenStack Compute (Nova) Improper Access Control
Moderate
CVE-2015-2687
was published
for
nova
(pip)
May 17, 2022
OpenStack Compute (Nova) Denial of service via a large number of calls to the addFixedIp function
High
CVE-2013-1838
was published
for
nova
(pip)
May 17, 2022
OpenStack Identity (Keystone) improper revoking of the authentication token when deleting a user
Moderate
CVE-2013-2059
was published
for
keystone
(pip)
May 17, 2022
OpenStack Nova Live migration can leak root disk into ephemeral storage
High
CVE-2013-7130
was published
for
nova
(pip)
May 17, 2022
Galaxy cross-site scripting (XSS)
Moderate
CVE-2018-1000516
was published
for
galaxy-app
(pip)
May 14, 2022
OpenStack Identity service (keystone) Incorrect Authorization
High
CVE-2017-2673
was published
for
keystone
(pip)
May 13, 2022
OpenStack Compute Nova Unauthorised access to arbitrary VM using VNC token from deleted VM
High
CVE-2013-0335
was published
for
Nova
(pip)
May 5, 2022
MoinMoin Multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2008-3381
was published
for
moin
(pip)
May 1, 2022
MoinMoin vulnerable to privilege escalation
High
CVE-2008-1937
was published
for
moin
(pip)
May 1, 2022
Plone Cross-site request forgery (CSRF)
High
CVE-2008-0164
was published
for
Plone
(pip)
May 1, 2022
Plone Arbitrary Code Execution via Unsafe Handling of Pickles
Critical
CVE-2007-5741
was published
for
plone
(pip)
May 1, 2022
Plone allows a user to masquerade as a group
Moderate
CVE-2006-4249
was published
for
Plone
(pip)
May 1, 2022
Plone allows anonymous users to reset any users password through the web via Password Reset Tool
High
CVE-2006-4247
was published
for
Plone
(pip)
May 1, 2022
Libextractor multiple heap-based buffer overflows
Moderate
CVE-2006-2458
was published
for
extractor
(pip)
May 1, 2022
Hard coded credentials in FreeTAKServer
High
CVE-2022-25510
was published
for
FreeTAKServer
(pip)
Mar 12, 2022
safeurl-python contains Server-Side Request Forgery
Moderate
CVE-2023-24622
was published
for
safeurl-python
(pip)
Jan 27, 2023
exotel-py includes code execution backdoor inserted by a third party
Critical
CVE-2022-38792
was published
for
exotel
(pip)
Aug 28, 2022
ansible-runner vulnerable to Race Condition
Moderate
CVE-2021-3702
was published
for
ansible-runner
(pip)
Aug 24, 2022
ansible-runner has default temporary files written to world R/W locations
Moderate
CVE-2021-3701
was published
for
ansible-runner
(pip)
Aug 24, 2022
OpenStack Cinder LVMVolumeDriver does not zero deleted snapshots
Moderate
CVE-2013-4183
was published
for
cinder
(pip)
May 17, 2022
Designate mDNS DoS through incorrect handling of large RecordSets
High
CVE-2015-5695
was published
for
designate
(pip)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API