GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,909
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,242
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
24,278 advisories
Filter by severity
usememos/memos vulnerable to improper access control
Moderate
CVE-2022-4685
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos Improper Access Control vulnerability
High
CVE-2022-4684
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos Authorization Bypass Through User-Controlled Key vulnerability
Critical
CVE-2022-4686
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos makes Incorrect Use of Privileged APIs
High
CVE-2022-4687
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos vulnerable to improper authorization
High
CVE-2022-4688
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos vulnerable to account takeover due to improper access control
High
CVE-2022-4689
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2022-4690
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
usememos/memos missing Secure cookie attribute
Moderate
CVE-2022-4683
was published
for
github.com/usememos/memos
(Go)
Dec 23, 2022
pypa/wheel vulnerable to Regular Expression denial of service (ReDoS)
High
CVE-2022-40898
was published
for
wheel
(pip)
Dec 23, 2022
Python Charmers Future denial of service vulnerability
High
CVE-2022-40899
was published
for
future
(pip)
Dec 23, 2022
pypa/setuptools vulnerable to Regular Expression Denial of Service (ReDoS)
High
CVE-2022-40897
was published
for
setuptools
(pip)
Dec 23, 2022
Collision of hash values in github.com/bnb-chain/tss-lib
Critical
CVE-2022-47931
was published
for
github.com/bnb-chain/tss-lib
(Go)
Dec 23, 2022
Tauri Filesystem Scope Glob Pattern is too Permissive
Moderate
CVE-2022-46171
was published
for
tauri
(Rust)
Dec 22, 2022
CodeIgniter4 Potential Session Handlers Vulnerability
High
CVE-2022-46170
was published
for
codeigniter4/framework
(Composer)
Dec 22, 2022
CodeIgniter4 allows spoofing of IP address when using proxy
High
CVE-2022-23556
was published
for
codeigniter4/framework
(Composer)
Dec 22, 2022
text_helpers uses web link to untrusted target with window.opener access
Moderate
CVE-2020-36624
was published
for
text_helpers
(RubyGems)
Dec 22, 2022
destiny.gg chat vulnerable to cross-site request forgery
High
CVE-2020-36625
was published
for
github.com/destinygg/chat
(Go)
Dec 22, 2022
Apache ShardingSphere-Proxy Incomplete Cleanup vulnerability
Critical
CVE-2022-45347
was published
for
org.apache.shardingsphere:shardingsphere-proxy
(Maven)
Dec 22, 2022
liquidjs may leak properties of a prototype
Moderate
CVE-2022-25948
was published
for
liquidjs
(npm)
Dec 22, 2022
jsonwebtoken's insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
Moderate
CVE-2022-23541
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
jsonwebtoken vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
Moderate
CVE-2022-23540
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
jsonwebtoken unrestricted key type could lead to legacy keys usage
High
CVE-2022-23539
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
jsonwebtoken has insecure input validation in jwt.verify function
High
CVE-2022-23529
was published
for
jsonwebtoken
(npm)
Dec 22, 2022
•
withdrawn
rdiffweb Open Redirect vulnerability
Moderate
CVE-2022-4644
was published
for
rdiffweb
(pip)
Dec 22, 2022
Microweber vulnerable to Stored Cross-Site Scripting
Moderate
CVE-2022-4647
was published
for
microweber/microweber
(Composer)
Dec 22, 2022
ProTip!
Advisories are also available from the
GraphQL API