GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Language support
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
3,988
Erlang
29
GitHub Actions
16
Go
1,776
Maven
5,000+
npm
3,542
NuGet
617
pip
3,125
Pub
10
RubyGems
838
Rust
790
Swift
34
Unreviewed advisories
All unreviewed
5,000+
8,693 advisories
Filter by severity
Moderate severity vulnerability that affects Plone
Moderate
CVE-2012-5503
was published
for
Plone
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects feedparser
Moderate
CVE-2011-1157
was published
for
feedparser
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Plone and Zope2
Moderate
CVE-2012-5489
was published
for
Plone
(pip)
Jul 23, 2018
HTTP header injection in Plone and Zope2
Moderate
CVE-2012-5486
was published
for
Plone
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects feedparser
Moderate
CVE-2011-1158
was published
for
feedparser
(pip)
Jul 23, 2018
Improper query string handling in Django
Moderate
CVE-2010-4534
was published
for
django
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Zope2
Moderate
CVE-2010-1104
was published
for
Zope2
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects django
Moderate
CVE-2011-4140
was published
for
django
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Plone and Zope2
Moderate
CVE-2012-6661
was published
for
Plone
(pip)
Jul 23, 2018
Cross-site request forgery in Django
Moderate
CVE-2011-0696
was published
for
django
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Plone and Zope2
Moderate
CVE-2012-5507
was published
for
Plone
(pip)
Jul 23, 2018
Cross-site scripting in Products.CMFPlone and Products.PasswordResetTool
Moderate
CVE-2011-1948
was published
for
Products.CMFPlone
(pip)
Jul 23, 2018
Plone Denial of Service vulnerability
Moderate
CVE-2011-4462
was published
for
Plone
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects feedparser
Moderate
CVE-2011-1156
was published
for
feedparser
(pip)
Jul 23, 2018
Moderate severity vulnerability that affects Products.PlonePAS
Moderate
CVE-2009-0662
was published
for
Products.PlonePAS
(pip)
Jul 23, 2018
Ciborg gem for Ruby allows local users to write files and gain privileges via Symlink
Moderate
CVE-2014-5003
was published
for
ciborg
(RubyGems)
Jul 23, 2018
Invalid Curve Attack in node-jose
Moderate
CVE-2017-16007
was published
for
node-jose
(npm)
Jul 20, 2018
Cross-site Scripting (XSS) - Stored in crud-file-server
Moderate
CVE-2018-3726
was published
for
crud-file-server
(npm)
Jul 18, 2018
Information Exposure on Case Insensitive File Systems in serve
Moderate
CVE-2018-3809
was published
for
serve
(npm)
Jul 18, 2018
Pysaml2 improperly initializes encryption vector
Moderate
CVE-2017-1000246
was published
for
pysaml2
(pip)
Jul 16, 2018
django-epiceditor vulnerable to XSS in form field
Moderate
CVE-2017-6591
was published
for
django-epiceditor
(pip)
Jul 13, 2018
python-fedora vulnerable to an open redirect resulting in loss of CSRF protection
Moderate
CVE-2017-1002150
was published
for
python-fedora
(pip)
Jul 13, 2018
ProTip!
Advisories are also available from the
GraphQL API