GitHub Advisory Database
4,176 advisories
Filter by severity
Observable Timing Discrepancy in aaugustin websockets library
CVE-2021-33880
(High severity)
was published Jun 11, 2021
•
websockets
(pip)
Exposure of Sensitive Information to an Unauthorized Actor in foreman_fog_proxmox
CVE-2021-20259
(High severity)
was published Jun 10, 2021
•
foreman_fog_proxmox
(RubyGems)
Path Traversal in Django
CVE-2021-33203
(Moderate severity)
was published Jun 10, 2021
•
django
(pip)
Bypass of access control in Django
CVE-2021-33571
(High severity)
was published Jun 10, 2021
•
django
(pip)
Authentication bypass in SilverStripe GraphQL
CVE-2020-26136
(High severity)
was published Jun 10, 2021
•
silverstripe/graphql
(Composer)
Path Traversal in Zope
CVE-2021-32674
(High severity)
was published Jun 10, 2021
•
Zope
(pip)
Reflected cross-site scripting issue in Datasette
CVE-2021-32670
(High severity)
was published Jun 10, 2021
•
datasette
(pip)
Uncontrolled Resource Consumption in locutus
CVE-2021-23392
(Moderate severity)
was published Jun 10, 2021
•
locutus
(npm)
Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability
CVE-2021-28169
(Moderate severity)
was published Jun 10, 2021
•
org.eclipse.jetty:jetty-servlets
(Maven)
Use of Cryptographically Weak Pseudo-Random Number Generator in Rclone
CVE-2020-28924
(High severity)
was published Jun 10, 2021
•
github.com/rclone/rclone
(Go)
Cross-Site Request Forgery (CSRF) in FastAPI
CVE-2021-32677
(Moderate severity)
was published Jun 10, 2021
•
fastapi
(pip)
Privilege Context Switching Error in wildlfy
CVE-2020-1719
(High severity)
was published Jun 8, 2021
•
org.wildfly.bom:wildfly
(Maven)
Remote Code Execution via traversal in TAL expressions
GHSA-rpcg-f9q6-2mq6
(High severity)
was published Jun 8, 2021
•
Zope
(pip)
Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2021-23391
(High severity)
was published Jun 8, 2021
•
calipso
(npm)
Remote Command Execution in reg-keygen-git-hash-plugin
CVE-2021-32673
(High severity)
was published Jun 8, 2021
•
reg-keygen-git-hash-plugin
(npm)
XSS vulnerability with translator
CVE-2021-32671
(Critical severity)
was published Jun 7, 2021
•
flarum/core
(Composer)
Reflected cross-site scripting issue in Datasette
GHSA-xw7c-jx9m-xh5g
(High severity)
was published Jun 7, 2021
•
datasette
(pip)
Deserialization of Untrusted Data
CVE-2017-5929
(Critical severity)
was published Jun 7, 2021
•
ch.qos.logback:logback-classic
(Maven)
XML Entity Expansion
CVE-2017-18640
(High severity)
was published Jun 4, 2021
•
org.yaml:snakeyaml
(Maven)
Invalid session token expiration
CVE-2021-32923
(High severity)
was published Jun 8, 2021
•
github.com/hashicorp/vault
(Go)
Prototype pollution
CVE-2021-25947
(Moderate severity)
was published Jun 7, 2021
•
nestie
(npm)
Regular expression denial of service
CVE-2020-28469
(Moderate severity)
was published Jun 7, 2021
•
glob-parent
(npm)
Reflected XSS when using flashMessages or languageDictionary
CVE-2021-32641
(High severity)
was published Jun 4, 2021
•
auth0-lock
(npm)
Generation of Error Message Containing Sensitive Information in RESTEasy client
CVE-2020-25633
(Moderate severity)
was published Jun 3, 2021
•
org.jboss.resteasy:resteasy-client
(Maven)
Script injection
CVE-2021-32660
(Moderate severity)
was published Jun 4, 2021
•
@backstage/techdocs-common
(npm)
ProTip!
Advisories are also available from the
GraphQL API