GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            19 advisories
        Filter by severity
        
      
      
    
                    
                      TemporaryFolder on unix-like systems does not limit access to created files
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-41946
                      
                      was published
                        for
                        
                          org.postgresql:postgresql
                        
                        (Maven)
                      Nov 23, 2022 
                    
                  
                    
                      Venice vulnerable to Partial Path Traversal issue within the functions `load-file` and `load-resource`
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-36007
                      
                      was published
                        for
                        
                          com.github.jlangch:venice
                        
                        (Maven)
                      Aug 18, 2022 
                    
                  
                    
                      Neo4j Graph apoc plugins Partial Path Traversal Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-37423
                      
                      was published
                        for
                        
                          org.neo4j.procedure:apoc
                        
                        (Maven)
                      Aug 12, 2022 
                    
                  
                    
                      Insufficiently Protected Credentials via Insecure Temporary File in org.apache.nifi:nifi-single-user-utils
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-26850
                      
                      was published
                        for
                        
                          org.apache.nifi:nifi-single-user-utils
                        
                        (Maven)
                      Jun 20, 2022 
                    
                  
                    
                      Local Information Disclosure Vulnerability in io.netty:netty-codec-http
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-24823
                      
                      was published
                        for
                        
                          io.netty:netty-codec-http
                        
                        (Maven)
                      May 10, 2022 
                    
                  
                    
                      Ratpack's default client side session signing key is highly predictable
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-29480
                      
                      was published
                        for
                        
                          io.ratpack:ratpack-session
                        
                        (Maven)
                      Jul 1, 2021 
                    
                  
                    
                      Unencrypted storage of client side sessions
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-29481
                      
                      was published
                        for
                        
                          io.ratpack:ratpack-session
                        
                        (Maven)
                      Jul 1, 2021 
                    
                  
                    
                      Creation of Temporary File in Directory with Insecure Permissions in auto-generated Java, Scala code
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21430
                      
                      was published
                        for
                        
                          org.openapitools:openapi-generator
                        
                        (Maven)
                      May 11, 2021 
                    
                  
                    
                      Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven plugin
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21429
                      
                      was published
                        for
                        
                          org.openapitools:openapi-generator-maven-plugin
                        
                        (Maven)
                      Apr 29, 2021 
                    
                  
                    
                      Local information disclosure via system temporary directory
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-28168
                      
                      was published
                        for
                        
                          org.glassfish.jersey.core:jersey-common
                        
                        (Maven)
                      Apr 23, 2021 
                    
                  
                    
                      Netflix/Priam: Temporary Directory Information Disclosure
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-28100
                      
                      was published
                        for
                        
                          com.netflix.priam:priam
                        
                        (Maven)
                      Mar 30, 2021 
                    
                  
                    
                      Generated Code Contains Local Information Disclosure Vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21364
                      
                      was published
                        for
                        
                          io.swagger:swagger-codegen
                        
                        (Maven)
                      Mar 11, 2021 
                    
                  
                    
                      Local Information Disclosure Vulnerability in Netty on Unix-Like systems
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21290
                      
                      was published
                        for
                        
                          io.netty:netty
                        
                        (Maven)
                      Feb 8, 2021 
                    
                  
                    
                      TemporaryFolder on unix-like systems does not limit access to created files
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-15250
                      
                      was published
                        for
                        
                          junit:junit
                        
                        (Maven)
                      Oct 12, 2020 
                    
                  
                    
                      HTTP Response Splitting in Styx
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-6858
                      
                      was published
                        for
                        
                          com.hotels.styx:styx-api
                        
                        (Maven)
                      Mar 3, 2020 
                    
                  
                    
                      XSS in dojox due to insufficient escape in dojox.xmpp.util.xmlEncode 
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-10785
                      
                      was published
                        for
                        
                          dojox
                        
                        (npm)
                      Feb 13, 2020 
                    
                  
                    
                      XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-10782
                      
                      was published
                        for
                        
                          com.puppycrawl.tools:checkstyle
                        
                        (Maven)
                      Jan 31, 2020 
                    
                  
                    
                      Default development error handler in Ratpack is vulnerable to HTML content injection (XSS)
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-10770
                      
                      was published
                        for
                        
                          io.ratpack:ratpack-core
                        
                        (Maven)
                      Jan 27, 2020 
                    
                  
                    
                      Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') in Armeria
                    
                      
  Moderate
                    
                
                      
                        GHSA-35fr-h7jr-hh86
                      
                      was published
                        for
                        
                          com.linecorp.armeria:armeria
                        
                        (Maven)
                      Dec 6, 2019 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API