Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

19 advisories

Loading
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability Moderate
CVE-2024-35255 was published for @azure/identity (Go) Jun 11, 2024
scottaddie localden
WordOps has TOCTOU race condition Moderate
CVE-2024-34528 was published for wordops (pip) May 6, 2024
VirtuBox
vantage6 vulnerable to a username timing attack on recover password/MFA token Moderate
CVE-2024-24770 was published for vantage6 (pip) Mar 15, 2024
Apache Airflow exposes arbitrary file content Moderate
CVE-2022-38170 was published for apache-airflow (pip) Sep 3, 2022
sunSUNQ
ansible-runner 2.0.0 vulnerable to Race Condition Moderate
CVE-2021-3702 was published for ansible-runner (pip) Aug 24, 2022
Uncaught Exception (due to a data race) leads to process termination in Waitress Moderate
CVE-2022-31015 was published for waitress (pip) Jun 2, 2022
oakkitten
Concurrent Execution using Shared Resource with Improper Synchronization in pyftpdlib Moderate
CVE-2010-3494 was published for pyftpdlib (pip) May 17, 2022
Zope Object Database Denial of Service vulnerability Moderate
CVE-2010-3495 was published for zodb3 (pip) May 17, 2022
OpenStack Neutron Race condition vulnerability Low
CVE-2015-5240 was published for neutron (pip) May 17, 2022
Radicale is vulnerable to timing oracles and simple bruteforce attacks High
CVE-2017-8342 was published for Radicale (pip) May 13, 2022
OpenStack Neutron Race Condition vulnerability Moderate
CVE-2017-7543 was published for neutron (pip) May 13, 2022
Race Condition in Paramiko Moderate
CVE-2022-24302 was published for paramiko (pip) Mar 19, 2022
ktosiek
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible Moderate
CVE-2020-10744 was published for ansible (pip) Feb 9, 2022
Exposure of Resource to Wrong Sphere and Insecure Temporary File in Ansible Moderate
CVE-2020-1733 was published for ansible (pip) Apr 20, 2021
Code Injection, Race Condition, and Execution with Unnecessary Privileges in Ansible High
CVE-2020-10684 was published for ansible (pip) Apr 7, 2021
Webargs mishandles concurrent JSON parsing High
CVE-2019-9710 was published for webargs (pip) Mar 12, 2019
Moderate severity vulnerability that affects Plone and Zope2 Moderate
CVE-2012-5507 was published for Plone (pip) Jul 23, 2018
ProTip! Advisories are also available from the GraphQL API