GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,272
Erlang
31
GitHub Actions
21
Go
2,049
Maven
5,000+
npm
3,739
NuGet
668
pip
3,417
Pub
12
RubyGems
891
Rust
868
Swift
36
Unreviewed advisories
All unreviewed
5,000+
259,367 advisories
Filter by severity
Jinja has a sandbox breakout through indirect reference to format method
Moderate
CVE-2024-56326
was published
for
jinja2
(pip)
Dec 23, 2024
Jinja has a sandbox breakout through malicious filenames
Moderate
CVE-2024-56201
was published
for
jinja2
(pip)
Dec 23, 2024
Path Traversal in file update API in gogs
Critical
CVE-2024-55947
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Remote Command Execution in file editing in gogs
Critical
CVE-2024-54148
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
Low
CVE-2024-52800
was published
for
org.verapdf:core
(Maven)
Dec 2, 2024
ASA-2024-0012, ASA-2024-0013: CosmosSDK: Transaction decoding may result in a stack overflow or resource exhaustion
High
GHSA-8wcc-m6j2-qxvm
was published
for
cosmossdk.io/x/tx
(Go)
Dec 16, 2024
CWA-2023-004: Excessive number of function parameters in compiled Wasm
Moderate
GHSA-75qh-gg76-p2w4
was published
for
cosmwasm-vm
(Go)
Aug 27, 2024
Keycloak's admin API allows low privilege users to use administrative functions
High
CVE-2024-3656
was published
for
org.keycloak:keycloak-services
(Maven)
Jun 11, 2024
Duplicate Advisory: Keycloak Open Redirect vulnerability
Moderate
GHSA-3p75-q5cc-qmj7
was published
for
org.keycloak:keycloak-parent
(Maven)
Dec 19, 2023
•
withdrawn
In the Linux kernel, the following vulnerability has been resolved:
backlight: hx8357: Fix...
Moderate
Unreviewed
CVE-2024-27071
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
media: go7007: fix a memleak...
Moderate
Unreviewed
CVE-2024-27074
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
nfs: fix UAF in direct...
High
Unreviewed
CVE-2024-26958
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
usb: xhci: Add error...
Moderate
Unreviewed
CVE-2024-26964
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
powercap: intel_rapl: Fix a...
Moderate
Unreviewed
CVE-2024-26975
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
thermal/drivers/mediatek...
Moderate
Unreviewed
CVE-2024-27068
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: gcc-ipq9574: fix...
Moderate
Unreviewed
CVE-2024-26968
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
bootconfig: use...
High
Unreviewed
CVE-2024-26983
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
mac802154: fix llsec key...
High
Unreviewed
CVE-2024-26961
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: mmcc-apq8084: fix...
Moderate
Unreviewed
CVE-2024-26966
was published
May 1, 2024
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
High
Unreviewed
CVE-2021-44207
was published
Dec 22, 2021
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: camcc-sc8280xp:...
Moderate
Unreviewed
CVE-2024-26967
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
clk: qcom: gcc-ipq8074: fix...
Moderate
Unreviewed
CVE-2024-26969
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: fix...
Moderate
Unreviewed
CVE-2024-27011
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: Fix a...
Moderate
Unreviewed
CVE-2024-27064
was published
May 1, 2024
In the Linux kernel, the following vulnerability has been resolved:
net/sched: Fix mirred...
Moderate
Unreviewed
CVE-2024-27010
was published
May 1, 2024
ProTip!
Advisories are also available from the
GraphQL API