GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,411
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
21,438 advisories
Filter by severity
ClusterLabs crmsh vulnerable to shell code injection
High
CVE-2020-35459
was published
for
crmsh
(pip)
May 24, 2022
Formstone Vulnerable to Reflected XSS
Moderate
CVE-2020-26768
was published
for
formstone
(npm)
May 24, 2022
Umbraco CMS vulnerable to stored XSS
Moderate
CVE-2020-5809
was published
for
UmbracoCms.Core
(NuGet)
May 24, 2022
Improper `Sync` implementation on `FuturesUnordered` in futures-utils can cause data corruption
Moderate
CVE-2020-35908
was published
for
futures-util
(Rust)
May 24, 2022
futures_task::noop_waker_ref can segfault due to dereferencing a NULL pointer
Moderate
CVE-2020-35907
was published
for
futures-task
(Rust)
May 24, 2022
MutexGuard::map can cause a data race in safe code
Moderate
CVE-2020-35905
was published
for
futures-util
(Rust)
May 24, 2022
futures_task::waker may cause a use-after-free if used on a type that isn't 'static
High
CVE-2020-35906
was published
for
futures-task
(Rust)
May 24, 2022
`net2` invalidly assumes the memory layout of std::net::SocketAddr
Moderate
CVE-2020-35919
was published
for
net2
(Rust)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29245
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29244
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
OpenCart Cross-site Scripting (XSS) in the Subject field of mail.
Moderate
CVE-2020-29470
was published
for
opencart/opencart
(Composer)
May 24, 2022
OpenCart Stored Cross-Site Scripting
Moderate
CVE-2020-29471
was published
for
opencart/opencart
(Composer)
May 24, 2022
dhowden tag panic due to out-of-bounds read
Moderate
CVE-2020-29243
was published
for
github.com/dhowden/tag
(Go)
May 24, 2022
dset vulnerable to prototype pollution
Critical
CVE-2020-28277
was published
for
dset
(npm)
May 24, 2022
WooCommerce Incorrect Authorization
Moderate
CVE-2020-29156
was published
for
woocommerce/woocommerce
(Composer)
May 24, 2022
flattenizer vulnerable to prototype pollution
Critical
CVE-2020-28279
was published
for
flattenizer
(npm)
May 24, 2022
Prototype pollution vulnerability in 'deep-set'
Critical
CVE-2020-28276
was published
for
deep-set
(npm)
May 24, 2022
shvl vulnerable to prototype pollution
Critical
CVE-2020-28278
was published
for
shvl
(npm)
May 24, 2022
Dangling reference in `access::Map` with Constant
High
CVE-2020-35711
was published
for
arc-swap
(Rust)
May 24, 2022
http before 0.13.3 vulnerable to header injection
Moderate
CVE-2020-35669
was published
for
http
(Pub)
May 24, 2022
Dolibarr authenticated Remote Code Execution
High
CVE-2020-35136
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Default inheritable capabilities for linux container should be empty
Moderate
CVE-2022-29162
was published
for
github.com/opencontainers/runc
(Go)
May 24, 2022
jsonpickle unsafe deserialization
Critical
CVE-2020-22083
was published
for
jsonpickle
(pip)
May 24, 2022
Keycloak vulnerable to Server-Side Request Forgery
Moderate
CVE-2020-10770
was published
for
org.keycloak:keycloak-core
(Maven)
May 24, 2022
QuantConnect Lean vulnerable to insecure deserialization
Critical
CVE-2020-20136
was published
for
QuantConnect.Common
(NuGet)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API