Skip to content

GitHub Advisory Database

Observable Timing Discrepancy in aaugustin websockets library
CVE-2021-33880 (High severity) was published Jun 11, 2021 websockets (pip)
Exposure of Sensitive Information to an Unauthorized Actor in foreman_fog_proxmox
CVE-2021-20259 (High severity) was published Jun 10, 2021 foreman_fog_proxmox (RubyGems)
Path Traversal in Django
CVE-2021-33203 (Moderate severity) was published Jun 10, 2021 django (pip)
Bypass of access control in Django
CVE-2021-33571 (High severity) was published Jun 10, 2021 django (pip)
Authentication bypass in SilverStripe GraphQL
CVE-2020-26136 (High severity) was published Jun 10, 2021 silverstripe/graphql (Composer)
Path Traversal in Zope
CVE-2021-32674 (High severity) was published Jun 10, 2021 Zope (pip)
Reflected cross-site scripting issue in Datasette
CVE-2021-32670 (High severity) was published Jun 10, 2021 datasette (pip)
Uncontrolled Resource Consumption in locutus
CVE-2021-23392 (Moderate severity) was published Jun 10, 2021 locutus (npm)
Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability
CVE-2021-28169 (Moderate severity) was published Jun 10, 2021 org.eclipse.jetty:jetty-servlets (Maven)
stevenseeley
Use of Cryptographically Weak Pseudo-Random Number Generator in Rclone
CVE-2020-28924 (High severity) was published Jun 10, 2021 github.com/rclone/rclone (Go)
Cross-Site Request Forgery (CSRF) in FastAPI
CVE-2021-32677 (Moderate severity) was published Jun 10, 2021 fastapi (pip)
b0g3r
Privilege Context Switching Error in wildlfy
CVE-2020-1719 (High severity) was published Jun 8, 2021 org.wildfly.bom:wildfly (Maven)
Remote Code Execution via traversal in TAL expressions
GHSA-rpcg-f9q6-2mq6 (High severity) was published Jun 8, 2021 Zope (pip)
Arbitrary File Write via Archive Extraction (Zip Slip)
CVE-2021-23391 (High severity) was published Jun 8, 2021 calipso (npm)
Remote Command Execution in reg-keygen-git-hash-plugin
CVE-2021-32673 (High severity) was published Jun 8, 2021 reg-keygen-git-hash-plugin (npm)
progfay
XSS vulnerability with translator
CVE-2021-32671 (Critical severity) was published Jun 7, 2021 flarum/core (Composer)
davwheat
Reflected cross-site scripting issue in Datasette
GHSA-xw7c-jx9m-xh5g (High severity) was published Jun 7, 2021 datasette (pip)
Deserialization of Untrusted Data
CVE-2017-5929 (Critical severity) was published Jun 7, 2021 ch.qos.logback:logback-classic (Maven)
XML Entity Expansion
CVE-2017-18640 (High severity) was published Jun 4, 2021 org.yaml:snakeyaml (Maven)
Invalid session token expiration
CVE-2021-32923 (High severity) was published Jun 8, 2021 github.com/hashicorp/vault (Go)
Prototype pollution
CVE-2021-25947 (Moderate severity) was published Jun 7, 2021 nestie (npm)
Regular expression denial of service
CVE-2020-28469 (Moderate severity) was published Jun 7, 2021 glob-parent (npm)
Reflected XSS when using flashMessages or languageDictionary
CVE-2021-32641 (High severity) was published Jun 4, 2021 auth0-lock (npm)
Generation of Error Message Containing Sensitive Information in RESTEasy client
CVE-2020-25633 (Moderate severity) was published Jun 3, 2021 org.jboss.resteasy:resteasy-client (Maven)
Script injection
CVE-2021-32660 (Moderate severity) was published Jun 4, 2021 @backstage/techdocs-common (npm)
ProTip! Advisories are also available from the GraphQL API