GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
25,028 advisories
Filter by severity
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1245
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Answer vulnerable to Cross-site Scripting
Moderate
CVE-2023-1244
was published
for
github.com/answerdev/answer
(Go)
Mar 7, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2021-36399
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle Cross-site Scripting vulnerability
Moderate
CVE-2021-36398
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle has Incorrect Default Permissions
Moderate
CVE-2021-36397
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle vulnerable to Stored Cross-site Scripting
Moderate
CVE-2021-36401
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
openstack-neutron uncontrolled resource consumption flaw
Moderate
CVE-2022-3277
was published
for
neutron
(pip)
Mar 7, 2023
Moodle has a Hidden Functionality vulnerability
Moderate
CVE-2021-36403
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle Improper Input Validation vulnerability
Moderate
CVE-2021-36402
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Moodle has Incorrect Default Permissions
Moderate
CVE-2021-36400
was published
for
moodle/moodle
(Composer)
Mar 7, 2023
Insufficient Session Expiration in pretix
High
CVE-2023-27891
was published
for
pretix
(pip)
Mar 7, 2023
OpenStack Glance Inclusion of Functionality from Untrusted Control Sphere vulnerability
Low
CVE-2022-4134
was published
for
glance
(pip)
Mar 7, 2023
Moodle vulnerable to Server-Side Request Forgery
High
CVE-2021-36396
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle Session Fixation vulnerability
Critical
CVE-2021-36394
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle vulnerable to Uncontrolled Resource Consumption
High
CVE-2021-36395
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle SQL Injection vulnerability
Critical
CVE-2021-36392
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle SQL Injection vulnerability
Critical
CVE-2021-36393
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Remote code execution in Funadmin
Critical
CVE-2023-24776
was published
for
funadmin/funadmin
(Composer)
Mar 6, 2023
jeecg-boot contains SQL Injection vulnerability
High
CVE-2023-24789
was published
for
org.jeecgframework.boot:jeecg-boot-parent
(Maven)
Mar 6, 2023
uvdesk/community-skeleton vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-1197
was published
for
uvdesk/community-skeleton
(Composer)
Mar 6, 2023
node-static and @nubosoftware/node-static vulnerable to Directory Traversal
High
CVE-2023-26111
was published
for
@nubosoftware/node-static
(npm)
Mar 6, 2023
SketchSVG Arbitrary Code Injection vulnerability
High
CVE-2023-26107
was published
for
sketchsvg
(npm)
Mar 6, 2023
dot-lens vulnerable to Prototype Pollution
High
CVE-2023-26106
was published
for
dot-lens
(npm)
Mar 6, 2023
@nestjs/core vulnerable to Information Exposure via StreamableFile pipe
Moderate
CVE-2023-26108
was published
for
@nestjs/core
(npm)
Mar 6, 2023
ProTip!
Advisories are also available from the
GraphQL API