GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,238
Erlang
31
GitHub Actions
21
Go
2,005
Maven
5,000+
npm
3,716
NuGet
661
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
233 advisories
Filter by severity
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS...
Moderate
Unreviewed
CVE-2023-44190
was published
Oct 12, 2023
An Origin Validation vulnerability in MAC address validation of Juniper Networks Junos OS...
Moderate
Unreviewed
CVE-2023-44189
was published
Oct 12, 2023
Movim prior to version 0.22 is affected by a Cross-Site WebSocket Hijacking vulnerability. This...
High
Unreviewed
CVE-2023-2848
was published
Sep 14, 2023
An issue was discovered in Zoho ManageEngine Network Configuration Manager 12.6.165. The...
High
Unreviewed
CVE-2023-29505
was published
Aug 4, 2023
Offscreen Canvas did not properly track cross-origin tainting, which could have been used to...
Moderate
Unreviewed
CVE-2023-4045
was published
Aug 1, 2023
A missing origin validation in Slate sandbox could be exploited by a malicious user to modify the...
Moderate
Unreviewed
CVE-2023-30949
was published
Jul 26, 2023
Mattermost fails to properly validate the origin of a websocket connection allowing a MITM...
High
Unreviewed
CVE-2023-3581
was published
Jul 17, 2023
In notification access permission dialog box, malicious application can embedded a very long...
Moderate
Unreviewed
CVE-2023-21260
was published
Jul 13, 2023
An issue was discovered in Gitpod versions prior to release-2022.11.2.16. There is a Cross-Site...
Critical
Unreviewed
CVE-2023-0957
was published
Jul 6, 2023
The underlying feedback mechanism of
Rockwell Automation's FactoryTalk System Services that...
Moderate
Unreviewed
CVE-2023-2639
was published
Jun 13, 2023
Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab...
Moderate
Unreviewed
CVE-2023-23601
was published
Jun 2, 2023
A security feature bypass vulnerability exists when Microsoft Edge improperly handles extension...
Moderate
Unreviewed
CVE-2019-1413
was published
May 24, 2022
An exploitable denial-of-service vulnerability exists in the 802.11w security state handling for...
Moderate
Unreviewed
CVE-2019-5062
was published
May 24, 2022
An issue was discovered in TitanHQ WebTitan before 5.18. It contains a Remote Code Execution...
High
Unreviewed
CVE-2019-19019
was published
May 24, 2022
hostapd before 2.10 and wpa_supplicant before 2.10 allow an incorrect indication of disconnection...
Moderate
Unreviewed
CVE-2019-16275
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep...
High
Unreviewed
CVE-2019-16235
was published
May 24, 2022
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep...
High
Unreviewed
CVE-2019-16237
was published
May 24, 2022
Images from a different domain can be read using a canvas object in some circumstances. This...
Moderate
Unreviewed
CVE-2019-9817
was published
May 24, 2022
If WebRTC permission is requested from documents with data: or blob: URLs, the permission...
Moderate
Unreviewed
CVE-2019-9808
was published
May 24, 2022
The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content...
High
Unreviewed
CVE-2019-9803
was published
May 24, 2022
Cross-origin images can be read in violation of the same-origin policy by exporting an image...
Moderate
Unreviewed
CVE-2019-9797
was published
May 24, 2022
An unauthenticated remote attacker can perform a remote code execution due to an origin...
Moderate
Unreviewed
CVE-2024-25996
was published
Mar 12, 2024
A vulnerability was found in lukehutch Gribbit. It has been classified as problematic. Affected...
Critical
Unreviewed
CVE-2014-125071
was published
Jan 9, 2023
Fiber has Insecure CORS Configuration, Allowing Wildcard Origin with Credentials
Critical
CVE-2024-25124
was published
for
github.com/gofiber/fiber/v2
(Go)
Feb 22, 2024
MeshCentral cross-site websocket hijacking (CSWSH) vulnerability
High
CVE-2024-26135
was published
for
meshcentral
(npm)
Feb 21, 2024
ProTip!
Advisories are also available from the
GraphQL API