GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,945
Erlang
29
GitHub Actions
16
Go
1,731
Maven
4,961
npm
3,493
NuGet
607
pip
3,059
Pub
10
RubyGems
832
Rust
778
Swift
34
Unreviewed advisories
All unreviewed
5,000+
19,269 advisories
Filter by severity
Unauthenticated Access to sensitive settings in Argo CD
Moderate
CVE-2024-37152
was published
for
github.com/argoproj/argo-cd/v2/server
(Go)
Jun 6, 2024
Jupyter server on Windows discloses Windows user password hash
High
CVE-2024-35178
was published
for
jupyter_server
(pip)
Jun 6, 2024
Evmos allows unvested token delegations
Moderate
CVE-2024-37154
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
Argo-cd authenticated users can enumerate clusters by name
Moderate
CVE-2024-36106
was published
for
github.com/argoproj/argo-cd
(Go)
Jun 6, 2024
Contract balance not updating correctly after interchain transaction
High
CVE-2024-37153
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
Remote code execution in pytorch lightning
Critical
CVE-2024-5452
was published
for
lightning
(pip)
Jun 6, 2024
evmos allows transferring unvested tokens after delegations
Low
CVE-2024-32873
was published
for
github.com/evmos/evmos/v10
(Go)
Jun 6, 2024
s2n-tls has a potentially observable differences in RSA premaster secret handling
Low
GHSA-52xf-5p2m-9wrv
was published
for
s2n-tls
(Rust)
Jun 6, 2024
Password hash exposed in CraftCMS two factor authentication plugin
Low
CVE-2024-5657
was published
for
born05/craft-twofactorauthentication
(Composer)
Jun 6, 2024
Improper Authentication in CraftCMS two factor authentication plugin
Moderate
CVE-2024-5658
was published
for
born05/craft-twofactorauthentication
(Composer)
Jun 6, 2024
typo3 Security fix for Flow Swift Mailer package
High
GHSA-xjw3-5r5c-m5ph
was published
for
typo3/swiftmailer
(Composer)
Jun 5, 2024
Insecure Unserialize Vulnerability in FLOW3
Moderate
GHSA-m2hp-5x78-74mg
was published
for
typo3/flow
(Composer)
Jun 5, 2024
typo3 Information Disclosure Security Note
High
GHSA-g4xv-r3qw-v3q2
was published
for
typo3/neos
(Composer)
Jun 5, 2024
Typo3 Arbitrary file upload and XML External Entity processing
Moderate
GHSA-2p4f-vc9q-r5vp
was published
for
typo3/flow
(Composer)
Jun 5, 2024
By-passing Protection of PharStreamWrapper Interceptor
Moderate
GHSA-4v5g-8pq2-32m2
was published
for
typo3/phar-stream-wrapper
(Composer)
Jun 5, 2024
Time-Based Information Disclosure Vulnerability in Flow
Moderate
GHSA-r6mm-wmhf-849m
was published
for
typo3/flow
(Composer)
Jun 5, 2024
Privilege Escalation in TYPO3 Neos
Moderate
GHSA-wr3c-6c22-m9v6
was published
for
typo3/neos
(Composer)
Jun 5, 2024
Flow Bugfix Releases for Entity Security
High
GHSA-vh6j-wv25-8qxr
was published
for
typo3/flow
(Composer)
Jun 5, 2024
Cross-Site Scripting (XSS) vulnerabilities in Neos
High
GHSA-4542-p56h-8xww
was published
for
typo3/neos
(Composer)
Jun 5, 2024
Typo3 Cross-Site Scripting in Language Pack Handling
Moderate
GHSA-259v-xm34-p7fr
was published
for
typo3/cms
(Composer)
Jun 5, 2024
Typo3 Broken Access Control in Import Module
Moderate
GHSA-f5rr-9r84-wwqf
was published
for
typo3/cms
(Composer)
Jun 5, 2024
ProTip!
Advisories are also available from the
GraphQL API