GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
25,938 advisories
Filter by severity
Denial of service via HTTP/2 HEADERS frames padding
High
CVE-2022-0618
was published
for
github.com/apple/swift-nio-http2
(Swift)
Jun 9, 2023
LeafKit allows XSS with untrusted user input
Moderate
CVE-2021-37634
was published
for
github.com/vapor/leaf-kit
(Swift)
Jun 9, 2023
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
High
CVE-2021-36153
was published
for
github.com/grpc/grpc-swift
(Swift)
Jun 9, 2023
Uncontrolled Resource Consumption in LengthPrefixedMessageReader
High
CVE-2021-36155
was published
for
github.com/grpc/grpc-swift
(Swift)
Jun 9, 2023
Untrusted data fed into `Data.init(base32Encoded:)` can result in exposing server memory and/or crash
Moderate
CVE-2021-32742
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
Vapor's Metrics integration could cause a system drain
Moderate
CVE-2021-21328
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
Arbitrary file read using percent-encoded relative paths in FileMiddleware
Moderate
CVE-2020-15230
was published
for
github.com/vapor/vapor
(Swift)
Jun 9, 2023
Hashicorp Vault vulnerable to Cross-site Scripting
Moderate
CVE-2023-2121
was published
for
github.com/hashicorp/vault
(Go)
Jun 9, 2023
Froxlor vulnerable to Improper Restriction of Excessive Authentication Attempts
Critical
CVE-2023-3173
was published
for
froxlor/froxlor
(Composer)
Jun 9, 2023
Froxlor vulnerable to Path Traversal
High
CVE-2023-3172
was published
for
froxlor/froxlor
(Composer)
Jun 9, 2023
OpenZeppelin Contracts's governor proposal creation may be blocked by frontrunning
Moderate
CVE-2023-34234
was published
for
@openzeppelin/contracts
(npm)
Jun 8, 2023
RuoYi Uncontrolled Resource Consumption vulnerability
Low
CVE-2023-3163
was published
for
com.ruoyi:ruoyi
(Maven)
Jun 8, 2023
Jeecg P3 Biz Chat allows remote attackers to read arbitrary files
High
CVE-2023-33510
was published
for
org.jeecgframework.p3:jeecg-p3-biz-chat
(Maven)
Jun 7, 2023
xxl-rpc deserialization vulnerability
Critical
CVE-2023-33496
was published
for
com.xuxueli:xxl-rpc-core
(Maven)
Jun 7, 2023
Vapor vulnerable to denial of service in HTTP Range Request of FileMiddleware
High
CVE-2022-31005
was published
for
github.com/vapor/vapor
(Swift)
Jun 7, 2023
Vapor vulnerable to denial of service in URLEncodedFormDecoder
High
CVE-2022-31019
was published
for
github.com/vapor/vapor
(Swift)
Jun 7, 2023
Swift-corelibs-foundation denial of service in JSON decoding with JSONDecoder
High
CVE-2022-1642
was published
for
github.com/apple/swift-corelibs-foundation
(Swift)
Jun 7, 2023
SwiftNIO Extras vulnerable to improper detection of complete HTTP body decompression
High
CVE-2022-3252
was published
for
github.com/apple/swift-nio-extras
(Swift)
Jun 7, 2023
SwiftNIO vulnerable to Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
Moderate
CVE-2022-3215
was published
for
github.com/apple/swift-nio
(Swift)
Jun 7, 2023
Async HTTP Client has CRLF Injection vulnerability in HTTP request headers
High
CVE-2023-0040
was published
for
github.com/swift-server/async-http-client
(Swift)
Jun 7, 2023
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2023-3142
was published
for
microweber/microweber
(Composer)
Jun 7, 2023
alist Incorrect Access Control vulnerability
High
CVE-2023-33498
was published
for
github.com/alist-org/alist/v3
(Go)
Jun 7, 2023
Duplicate Advisory: Grafana Improper Access Control vulnerability
Moderate
GHSA-wm7r-3qxj-5xgq
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
•
withdrawn
Grafana Missing Synchronization vulnerability
High
CVE-2023-2801
was published
for
github.com/grafana/grafana
(Go)
Jun 6, 2023
RedCloth Regular Expression Denial of Service issue
High
CVE-2023-31606
was published
for
RedCloth
(RubyGems)
Jun 6, 2023
ProTip!
Advisories are also available from the
GraphQL API