GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,273
Erlang
31
GitHub Actions
21
Go
2,055
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
872
Swift
36
Unreviewed advisories
All unreviewed
5,000+
18 advisories
Filter by severity
Jinja has a sandbox breakout through malicious filenames
Moderate
CVE-2024-56201
was published
for
jinja2
(pip)
Dec 23, 2024
gitoxide-core does not neutralize special characters for terminals
Low
CVE-2024-43785
was published
for
gitoxide
(Rust)
Aug 22, 2024
RARLAB WinRAR before 7.00, on Windows, allows attackers to spoof the screen output via ANSI...
High
Unreviewed
CVE-2024-36052
was published
May 21, 2024
RARLAB WinRAR before 7.00, on Linux and UNIX platforms, allows attackers to spoof the screen...
High
Unreviewed
CVE-2024-33899
was published
Apr 29, 2024
wall in util-linux through 2.40, often installed with setgid tty permissions, allows escape...
Low
Unreviewed
CVE-2024-28085
was published
Mar 27, 2024
Deno's deno_runtime vulnerable to interactive permission prompt spoofing via improper ANSI stripping
High
CVE-2024-27936
was published
for
deno
(Rust)
Mar 5, 2024
Shescape on Windows escaping may be bypassed in threaded context
High
CVE-2023-40185
was published
for
shescape
(npm)
Aug 22, 2023
An authentication bypass exists on CyberPower PowerPanel Enterprise by failing to sanitize meta...
Critical
Unreviewed
CVE-2023-3265
was published
Aug 14, 2023
Mutagen list and monitor operations do not neutralize control characters in text controlled by remote endpoints
Low
CVE-2023-30844
was published
for
github.com/mutagen-io/mutagen
(Go)
May 5, 2023
Interactive `run` permission prompt spoofing via improper ANSI neutralization
High
CVE-2023-28446
was published
for
deno
(Rust)
Mar 24, 2023
XWiki Platform may allow privilege escalation to programming rights via user's first name
Critical
CVE-2023-26055
was published
for
org.xwiki.commons:xwiki-commons-xml
(Maven)
Mar 3, 2023
Denial of service (DoS) when processing Git credentials
Moderate
CVE-2022-43756
was published
for
github.com/rancher/wrangler
(Go)
Jan 25, 2023
Possible shell escape sequence injection vulnerability in Rack
Critical
CVE-2022-30123
was published
for
rack
(RubyGems)
May 27, 2022
** UNSUPPORTED WHEN ASSIGNED ** The administration web interface on Belkin Linksys WRT160NL 1.0...
High
Unreviewed
CVE-2021-25310
was published
May 24, 2022
RubyGems Code Injection vulnerability
Critical
CVE-2017-0899
was published
for
rubygems-update
(RubyGems)
May 13, 2022
The xterm terminal emulator in XFree86 4.2.0 and earlier allows attackers to modify the window...
High
Unreviewed
CVE-2003-0063
was published
Apr 29, 2022
kubectl ANSI escape characters not filtered
Low
CVE-2021-25743
was published
for
k8s.io/kubernetes
(Go)
Jan 8, 2022
Control character injection in console output in github.com/ipfs/go-ipfs
Moderate
CVE-2020-26283
was published
for
github.com/ipfs/go-ipfs
(Go)
Jun 23, 2021
ProTip!
Advisories are also available from the
GraphQL API