GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            24 advisories
        Filter by severity
        
      
      
    
                    
                      Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
                    
                      
  Low
                    
                
                      
                        CVE-2024-5967
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-ldap-federation
                        
                        (Maven)
                      Jun 21, 2024 
                    
                  
                    
                      Exposure of Sensitive Information in Elastic APM .NET Agent
                    
                      
  Low
                    
                
                      
                        CVE-2021-22143
                      
                      was published
                        for
                        
                          Elastic.Apm
                        
                        (NuGet)
                      Nov 22, 2023 
                    
                  
                    
                      Concrete CMS (previously concrete5) is vulnerable to stored XSS in uploaded file and folder names
                    
                      
  Low
                    
                
                      
                        CVE-2023-28819
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Apr 28, 2023 
                    
                  
                    
                      Missing Cryptographic Step in OWASP Enterprise Security API for Java
                    
                      
  Low
                    
                
                      
                        CVE-2013-5679
                      
                      was published
                        for
                        
                          org.owasp.esapi:esapi
                        
                        (Maven)
                      May 17, 2022 
                    
                  
                    
                      Moodle's login_as feature leaks information from external repositories
                    
                      
  Low
                    
                
                      
                        CVE-2013-1835
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module
                    
                      
  Low
                    
                
                      
                        CVE-2013-1833
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2014-2571
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle does not set the RISK_XSS bit for graders
                    
                      
  Low
                    
                
                      
                        CVE-2015-0216
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2015-3178
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle does not set the RISK_XSS bit for graders
                    
                      
  Low
                    
                
                      
                        CVE-2015-3174
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2015-2273
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to bypass intended login restrictions
                    
                      
  Low
                    
                
                      
                        CVE-2015-3179
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle allows attackers to upload files containing JavaScript
                    
                      
  Low
                    
                
                      
                        CVE-2014-7835
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2015-0212
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle multiple cross-site scripting (XSS) vulnerabilities
                    
                      
  Low
                    
                
                      
                        CVE-2014-3551
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2014-7830
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle cross-site scripting (XSS) vulnerability
                    
                      
  Low
                    
                
                      
                        CVE-2014-3544
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Cross-site scripting in Apache ActiveMQ
                    
                      
  Low
                    
                
                      
                        CVE-2010-0684
                      
                      was published
                        for
                        
                          org.apache.activemq:activemq-parent
                        
                        (Maven)
                      May 2, 2022 
                    
                  
                    
                      Apache Tomcat vulnerable to Cross-site Scripting
                    
                      
  Low
                    
                
                      
                        CVE-2007-2450
                      
                      was published
                        for
                        
                          org.apache.tomcat:tomcat
                        
                        (Maven)
                      May 1, 2022 
                    
                  
                    
                      Password stored in plain text by Jenkins Publish Over SSH Plugin
                    
                      
  Low
                    
                
                      
                        CVE-2022-23114
                      
                      was published
                        for
                        
                          org.jenkins-ci.plugins:publish-over-ssh
                        
                        (Maven)
                      Jan 13, 2022 
                    
                  
                    
                      Improper Restriction of XML External Entity Reference in org.springframework.integration:spring-integration-ws and org.springframework.integration:spring-integration-xml
                    
                      
  Low
                    
                
                      
                        CVE-2019-3772
                      
                      was published
                        for
                        
                          org.springframework.integration:spring-integration-ws
                        
                        (Maven)
                      Jan 25, 2019 
                    
                  
                    
                      Exposure of Sensitive Information to an Unauthorized Actor in Apache hive
                    
                      
  Low
                    
                
                      
                        CVE-2018-1284
                      
                      was published
                        for
                        
                          org.apache.hive:hive
                        
                        (Maven)
                      Nov 21, 2018 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API