Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

18,873 advisories

github.com/huandu/facebook may expose access_token in error message. Low
CVE-2024-35232 was published for github.com/huandu/facebook/v2 (Go) May 24, 2024
seiyab
Soot Infinite Loop vulnerability High
CVE-2023-46442 was published for org.soot-oss:soot (Maven) May 24, 2024
Kwik does not discard unused encryption keys Moderate
CVE-2024-22588 was published for tech.kwik:kwik (Maven) May 24, 2024
Jenkins Report Info Plugin Path Traversal vulnerability Moderate
CVE-2024-5273 was published for org.jenkins-ci.plugins:report-info (Maven) May 24, 2024
PHP Server Monitor vulnerable to Cross-site Scripting Moderate
CVE-2024-5312 was published for phpservermon/phpservermon (Composer) May 24, 2024
Dolibarr vulnerable to SQL Injection Critical
CVE-2024-5315 was published for dolibarr/dolibarr (Composer) May 24, 2024
Dolibarr vulnerable to SQL Injection Critical
CVE-2024-5314 was published for dolibarr/dolibarr (Composer) May 24, 2024
vxe-table Cross-site Scripting vulnerability Low
CVE-2023-1001 was published for vxe-table (npm) May 24, 2024
Pug allows JavaScript code execution if an application accepts untrusted input High
CVE-2024-36361 was published for pug (npm) May 24, 2024
silverstripe/framework ReadOnly transformation for formfields exploitable Moderate
GHSA-97jm-g33h-f46g was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Cross-site scripting vulnerability in VersionedRequestFilter Moderate
GHSA-mpqj-f4v3-334h was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing CSRF protection in login form Moderate
GHSA-vj2j-6g3w-4662 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Brute force bypass on default admin Critical
GHSA-8v6m-7f5v-hhx6 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in CMS Edit Page Moderate
GHSA-m8v7-x398-pxrf was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Hostname, IP and Protocol Spoofing through HTTP Headers Moderate
GHSA-87pf-7x99-5xc4 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe CSRF vulnerability in GridFieldAddExistingAutocompleter Moderate
GHSA-2hpc-mf4q-j885 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Missing security check on dev/build/defaults Moderate
GHSA-x5w2-wcr8-9q45 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe HtmlEditor embed url sanitisation Moderate
GHSA-qp29-wcc2-vmpc was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe Form field validation message XSS vulnerability Moderate
GHSA-j982-5jv7-v43r was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe framework is vulnerable to XSS in install.php Moderate
GHSA-mqf5-275h-gf6r was published for silverstripe/framework (Composer) May 23, 2024
SilverStripe Vulnerability on 'isDev', 'isTest' and 'flush' $_GET validation Moderate
GHSA-g4hp-pfvf-vm5w was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in dev/build returnURL Parameter Moderate
GHSA-hq4p-5mpr-jj9m was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe External redirection risk in Security?ReturnURL Moderate
GHSA-vp8p-c6xj-xpj7 was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe X-Forwarded-Host request hostname injection High
GHSA-25gq-jvx2-vg9x was published for silverstripe/framework (Composer) May 23, 2024
Silverstripe XSS in Director::force_redirect() Moderate
GHSA-jqp8-v74p-g8px was published for silverstripe/framework (Composer) May 23, 2024
ProTip! Advisories are also available from the GraphQL API