GitHub Advisory Database
3,527 advisories
Filter by severity
Denial of service (via resource exhaustion) due to improper input validation
CVE-2021-29433
(Moderate severity)
was published Apr 16, 2021
•
matrix-sydent
(pip)
SQL Injection via in django-debug-toolbar
CVE-2021-30459
(High severity)
was published Apr 16, 2021
•
django-debug-toolbar
(pip)
Twig allowing dangerous PHP functions by default in getgrav/grav
CVE-2021-29440
(High severity)
was published Apr 16, 2021
•
getgrav/grav
(Composer)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogs
CVE-2021-29438
(Moderate severity)
was published Apr 16, 2021
•
@nextcloud/dialogs
(npm)
JavaScript execution via malicious molfiles (XSS)
GHSA-2pwh-52h7-7j84
(Moderate severity)
was published Apr 16, 2021
•
de.ipb-halle:molecularfaces
(Maven)
RSA signature validation vulnerability on maleable encoded message in jsrsasign
CVE-2021-30246
(Low severity)
was published Apr 16, 2021
•
jsrsasign
(npm)
Cross-Site Request Forgery (CSRF) in trestle-auth
CVE-2021-29435
(High severity)
was published Apr 13, 2021
•
trestle-auth
(RubyGems)
Improper parsing of octal bytes
CVE-2021-28918
(Critical severity)
was published Apr 14, 2021
•
netmask
(npm)
After order payment process manipulation in shopware/platform and shopware/core
GHSA-88rc-3p98-rgvx
(Critical severity)
was published Apr 13, 2021
•
shopware/core
(Composer)
Exposure of .env if project root is configured as web root in shopware/production
GHSA-3pcr-4982-548m
(Moderate severity)
was published Apr 13, 2021
•
shopware/production
(Composer)
Leak of information via Store-API aggregations in shopware/platform and shopware/core
GHSA-qg7c-q3vq-rgxr
(Critical severity)
was published Apr 13, 2021
•
shopware/core
(Composer)
Out-of-bounds Write in Chakra
CVE-2020-17131
(High severity)
was published Apr 13, 2021
•
Microsoft.ChakraCore
(NuGet)
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21392
(Moderate severity)
was published Apr 13, 2021
•
matrix-synapse
(pip)
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21394
(Moderate severity)
was published Apr 13, 2021
•
matrix-synapse
(pip)
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21393
(Moderate severity)
was published Apr 13, 2021
•
matrix-synapse
(pip)
User (Encrypted) Password Field Being Serialised
GHSA-7fjp-g4m7-fx23
(Low severity)
was published Apr 13, 2021
•
pwweb/laravel-core
(Composer)
Potential API key leak
GHSA-63rq-p8fp-524q
(Moderate severity)
was published Apr 13, 2021
•
sopel-modules.weather
(pip)
Prototype Pollution in set-or-get
CVE-2021-25913
(Critical severity)
was published Apr 12, 2021
•
set-or-get
(npm)
Exposure of Resource to Wrong Sphere in valib
CVE-2019-10805
(Moderate severity)
was published Apr 13, 2021
•
valib
(npm)
Incorrect permission enforcement in UmbracoCms
CVE-2020-29454
(Moderate severity)
was published Apr 13, 2021
•
UmbracoCms
(NuGet)
OS Command Injection in giting
CVE-2019-10802
(High severity)
was published Apr 13, 2021
•
seria-number
(npm)
OS Command Injection in serial-number
CVE-2019-10804
(High severity)
was published Apr 13, 2021
•
serial-number
(npm)
Improper Authentication in react-adal
CVE-2020-7787
(High severity)
was published Apr 13, 2021
•
react-adal
(npm)
Improper Input Validation in sopel-plugins.channelmgnt
CVE-2021-21431
(High severity)
was published Apr 9, 2021
•
sopel-plugins.channelmgnt
(pip)
OS Command Injection in enpeem
CVE-2019-10801
(High severity)
was published Apr 13, 2021
•
enpeem
(npm)
ProTip!
Advisories are also available from the
GraphQL API