GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,285
Erlang
31
GitHub Actions
21
Go
2,057
Maven
5,000+
npm
3,742
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
220 advisories
Filter by severity
XWiki Platform vulnerable to privilege escalation from view right on XWiki.Notifications.Code.LegacyNotificationAdministration
Critical
CVE-2023-29525
was published
for
org.xwiki.platform:xwiki-platform-distribution-war
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to code injection in display method used in user profiles
Critical
CVE-2023-29523
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 20, 2023
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector
Critical
CVE-2023-29516
was published
for
org.xwiki.platform:xwiki-platform-attachment-ui
(Maven)
Apr 20, 2023
XWiki Platform's async and display macro allow displaying and interacting with any document in restricted mode
Critical
CVE-2023-29526
was published
for
org.xwiki.platform:xwiki-platform-oldcore
(Maven)
Apr 20, 2023
Code injection in Duke
Critical
CVE-2023-39013
was published
for
no.priv.garshol.duke:duke
(Maven)
Jul 28, 2023
Cachet vulnerable to Authenticated Remote Code Execution
Critical
CVE-2023-43661
was published
for
cachethq/cachet
(Composer)
Oct 16, 2023
langchain vulnerable to arbitrary code execution
Critical
CVE-2023-36188
was published
for
langchain
(pip)
Jul 6, 2023
org.xwiki.commons:xwiki-commons-xml's HTML sanitizer allows form elements in restricted
Critical
CVE-2023-36471
was published
for
org.xwiki.commons:xwiki-commons-xml
(Maven)
Jun 30, 2023
org.xwiki.platform:xwiki-platform-skin-ui Eval Injection vulnerability
Critical
CVE-2023-37462
was published
for
org.xwiki.platform:xwiki-platform-skin-ui
(Maven)
Jul 14, 2023
PandasAI vulnerable to arbitrary code execution
Critical
CVE-2023-39661
was published
for
pandasai
(pip)
Aug 15, 2023
Strapi plugins vulnerable to Server-Side Template Injection and Remote Code Execution in the Users-Permissions Plugin
Critical
CVE-2023-22621
was published
for
@strapi/plugin-email
(npm)
Apr 19, 2023
org.xwiki.platform:xwiki-platform-logging-ui Eval Injection vulnerability
Critical
CVE-2023-29213
was published
for
org.xwiki.platform:xwiki-platform-logging-ui
(Maven)
Apr 12, 2023
Remote Code Execution for 2.4.1 and earlier
Critical
CVE-2023-36812
was published
for
net.opentsdb:opentsdb
(Maven)
Jun 30, 2023
Code injection via unescaped translations in xwiki-platform
Critical
CVE-2023-29510
was published
for
org.xwiki.platform:xwiki-platform-administration-ui
(Maven)
Apr 19, 2023
XWiki Platform vulnerable to Code injection through NotificationRSSService
Critical
CVE-2023-36469
was published
for
org.xwiki.platform:xwiki-platform-notifications-ui
(Maven)
Jun 30, 2023
XWiki Platform vulnerable to Code Injection in icon themes
Critical
CVE-2023-36470
was published
for
org.xwiki.platform:xwiki-platform-icon-default
(Maven)
Jun 30, 2023
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user...
Critical
Unreviewed
CVE-2023-5340
was published
Nov 20, 2023
Prototype Pollution in handlebars
Critical
CVE-2019-19919
was published
for
bootstrap-wysihtml5-rails
(RubyGems)
Dec 26, 2019
Guests can trigger NIC interface reset/abort/crash via netback It is possible for a guest to...
Critical
Unreviewed
CVE-2022-3643
was published
Dec 7, 2022
Usedesk before 1.7.57 allows chat template injection.
Critical
Unreviewed
CVE-2023-49214
was published
Nov 24, 2023
HtmlUnit Code Injection vulnerability
Critical
CVE-2023-26119
was published
for
net.sourceforge.htmlunit:htmlunit
(Maven)
Jul 6, 2023
This Template Injection vulnerability allows an authenticated attacker, including one with...
Critical
Unreviewed
CVE-2023-22522
was published
Dec 6, 2023
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell...
Critical
Unreviewed
CVE-2023-46456
was published
Dec 12, 2023
ProTip!
Advisories are also available from the
GraphQL API