Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

20,927 advisories

Loading
keycloak vulnerable to unauthorized login via mail server setup Critical
CVE-2019-14837 was published for org.keycloak:keycloak-core (Maven) May 24, 2022
jhutchings1
Moodle does not revoke role capabilities correctly Moderate
CVE-2019-14879 was published for moodle/moodle (Composer) May 24, 2022
HashBrown CMS Directory Traversal High
CVE-2020-5840 was published for hashbrown-cms (npm) May 24, 2022
Buffer Copy without Checking Size of Input in Pillow Critical
CVE-2020-5311 was published for pillow (pip) May 24, 2022
Pivotal Spring Framework contains unsafe Java deserialization methods Critical
CVE-2016-1000027 was published for org.springframework:spring-web (Maven) May 24, 2022
bclozel
Bolt Cross-site Scripting via the slug, teaser or title parameters Moderate
CVE-2019-9553 was published for bolt/bolt (Composer) May 24, 2022
php-shellcommand command injection vulnerability Critical
CVE-2019-10774 was published for mikehaertl/php-shellcommand (Composer) May 24, 2022
Athenz vulnerable to Open Redirect Moderate
CVE-2019-6035 was published for com.yahoo.athenz:athenz (Maven) May 24, 2022
Improper Neutralization of Input During Web Page Generation in swagger-ui Moderate
CVE-2016-1000229 was published for swagger-ui (npm) May 24, 2022
SwiftNIO SSL arbitrary code execution vulnerability Critical
CVE-2019-8849 was published for github.com/apple/swift-nio-ssl (Swift) May 24, 2022
Singularity insecure permissions High
CVE-2019-19724 was published for github.com/sylabs/singularity (Go) May 24, 2022
Treekill Enables OS Command Injection Critical
CVE-2019-15598 was published for tree-kill (npm) May 24, 2022
Duplicate Advisory: tree-kill vulnerable to remote code execution Critical
GHSA-mxq6-vrrr-ppmg was published for tree-kill (npm) May 24, 2022 withdrawn
yasinsd
TYPO3 SQL Injection in low-level Query Generator Moderate
CVE-2019-19850 was published for typo3/cms (Composer) May 24, 2022
TYPO3 Directory Traversal on ZIP extraction Moderate
CVE-2019-19848 was published for typo3/cms (Composer) May 24, 2022
TYPO3 Insecure Deserialization in Query Generator & Query View High
CVE-2019-19849 was published for typo3/cms (Composer) May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin allows attackers with Overall/Read permission to capture credentials stored in Jenkins Moderate
CVE-2019-16574 was published for com.alauda.jenkins.plugins:alauda-devops-pipeline (Maven) May 24, 2022
Cross-Site Request Forgery in Jenkins Alauda Kubernetes Suport Plugin High
CVE-2019-16575 was published for io.alauda.jenkins.plugins:alauda-kubernetes-support (Maven) May 24, 2022
Improper Authorization in Jenkins Alauda Kubernetes Suport Plugin Moderate
CVE-2019-16576 was published for io.alauda.jenkins.plugins:alauda-kubernetes-support (Maven) May 24, 2022
Jenkins Weibo Plugin stores credentials unencrypted in its global configuration file Low
CVE-2019-16572 was published for org.jenkins-ci.plugins:weibo (Maven) May 24, 2022
Jenkins Alauda DevOps Pipeline Plugin vulnerable to cross-site request forgery High
CVE-2019-16573 was published for com.alauda.jenkins.plugins:alauda-devops-pipeline (Maven) May 24, 2022
Jenkins SCTMExecutor Plugin stores credentials in plain text Moderate
CVE-2019-16568 was published for hudson.plugins.sctmexecutor:SCTMExecutor (Maven) May 24, 2022
CSRF vulnerability in Jenkins Mantis Plugin Moderate
CVE-2019-16569 was published for org.jenkins-ci.plugins:mantis (Maven) May 24, 2022
Jenkins Team Concert Plugin missing permission check Moderate
CVE-2019-16567 was published for org.jenkins-ci.plugins:teamconcert (Maven) May 24, 2022
Jenkins Team Concert Plugin missing permission check High
CVE-2019-16566 was published for org.jenkins-ci.plugins:teamconcert (Maven) May 24, 2022
ProTip! Advisories are also available from the GraphQL API