GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,747
Erlang
35
GitHub Actions
29
Go
2,321
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
921
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
18 advisories
Filter by severity
A vulnerability in the web application of ctrlX OS allows a remote unauthenticated attacker to...
Moderate
Unreviewed
CVE-2025-24339
was published
Apr 30, 2025
IBM i 7.3, 7.4, 7.5, and 7.5 is vulnerable to a host header injection attack caused by improper...
Moderate
Unreviewed
CVE-2025-2950
was published
Apr 21, 2025
IBM Aspera Console 3.4.0 through 3.4.4
is vulnerable to HTTP header injection, caused by...
Moderate
Unreviewed
CVE-2022-43847
was published
Apr 14, 2025
IBM TXSeries for Multiplatforms 9.1 and 11.1 could disclose sensitive information to a remote...
Moderate
Unreviewed
CVE-2025-0154
was published
Apr 2, 2025
IBM Control Center 6.2.1 through 6.3.1 is vulnerable to HTTP header injection, caused by improper...
Moderate
Unreviewed
CVE-2023-35894
was published
Mar 7, 2025
A Host Header Injection vulnerability exists in CTFd 3.7.5, due to the application failing to...
Moderate
Unreviewed
CVE-2025-23001
was published
Jan 31, 2025
IBM i 7.3, 7.4, and 7.5 is vulnerable to bypassing Navigator for i interface restrictions. By...
Moderate
Unreviewed
CVE-2024-51464
was published
Dec 21, 2024
The HTTP host header can be manipulated and cause the application to behave in unexpected ways....
Moderate
Unreviewed
CVE-2024-30129
was published
Dec 6, 2024
Hashicorp Consul Improper Neutralization of HTTP Headers for Scripting Syntax vulnerability
Moderate
CVE-2024-10006
was published
for
github.com/hashicorp/consul
(Go)
Oct 31, 2024
IBM Aspera Orchestrator 4.0.1 is vulnerable to HTTP header injection, caused by improper...
Moderate
Unreviewed
CVE-2023-26289
was published
Jul 30, 2024
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 is vulnerable to HTTP header...
Moderate
Unreviewed
CVE-2024-39736
was published
Jul 15, 2024
IBM Aspera Faspex 5.0.0 and 5.0.1 is vulnerable to HTTP header injection, caused by improper...
Moderate
Unreviewed
CVE-2022-22399
was published
Mar 5, 2024
Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security
Moderate
CVE-2024-21499
was published
for
github.com/greenpau/caddy-security
(Go)
Feb 17, 2024
IBM Engineering Lifecycle Optimization 7.0.2 and 7.0.3 is vulnerable to HTTP header injection,...
Moderate
Unreviewed
CVE-2023-45190
was published
Feb 9, 2024
Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
Moderate
CVE-2023-34036
was published
for
org.springframework.hateoas:spring-hateoas
(Maven)
Jul 17, 2023
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10,...
Moderate
Unreviewed
CVE-2023-36919
was published
Jul 11, 2023
HTTP header injection vulnerability in Everything all versions except the Lite version may allow...
Moderate
Unreviewed
CVE-2021-20784
was published
May 24, 2022
HTTP Host Header Injection
Moderate
CVE-2021-41114
was published
for
typo3/cms
(Composer)
Oct 5, 2021
ProTip!
Advisories are also available from the
GraphQL API