Skip to content

GitHub Advisory Database

3,527 advisories

Denial of service (via resource exhaustion) due to improper input validation
CVE-2021-29433 (Moderate severity) was published Apr 16, 2021 matrix-sydent (pip)
SQL Injection via in django-debug-toolbar
CVE-2021-30459 (High severity) was published Apr 16, 2021 django-debug-toolbar (pip)
alex
Twig allowing dangerous PHP functions by default in getgrav/grav
CVE-2021-29440 (High severity) was published Apr 16, 2021 getgrav/grav (Composer)
thomas-chauchefoin-sonarsource
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in @nextcloud/dialogs
CVE-2021-29438 (Moderate severity) was published Apr 16, 2021 @nextcloud/dialogs (npm)
solov9ev
JavaScript execution via malicious molfiles (XSS)
GHSA-2pwh-52h7-7j84 (Moderate severity) was published Apr 16, 2021 de.ipb-halle:molecularfaces (Maven)
RSA signature validation vulnerability on maleable encoded message in jsrsasign
CVE-2021-30246 (Low severity) was published Apr 16, 2021 jsrsasign (npm)
Cross-Site Request Forgery (CSRF) in trestle-auth
CVE-2021-29435 (High severity) was published Apr 13, 2021 trestle-auth (RubyGems)
tomekr aj-hall
utkanos
Improper parsing of octal bytes
CVE-2021-28918 (Critical severity) was published Apr 14, 2021 netmask (npm)
After order payment process manipulation in shopware/platform and shopware/core
GHSA-88rc-3p98-rgvx (Critical severity) was published Apr 13, 2021 shopware/core (Composer)
Exposure of .env if project root is configured as web root in shopware/production
GHSA-3pcr-4982-548m (Moderate severity) was published Apr 13, 2021 shopware/production (Composer)
Leak of information via Store-API aggregations in shopware/platform and shopware/core
GHSA-qg7c-q3vq-rgxr (Critical severity) was published Apr 13, 2021 shopware/core (Composer)
Out-of-bounds Write in Chakra
CVE-2020-17131 (High severity) was published Apr 13, 2021 Microsoft.ChakraCore (NuGet)
Open redirect via transitional IPv6 addresses on dual-stack networks
CVE-2021-21392 (Moderate severity) was published Apr 13, 2021 matrix-synapse (pip)
mscherer
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
CVE-2021-21394 (Moderate severity) was published Apr 13, 2021 matrix-synapse (pip)
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
CVE-2021-21393 (Moderate severity) was published Apr 13, 2021 matrix-synapse (pip)
User (Encrypted) Password Field Being Serialised
GHSA-7fjp-g4m7-fx23 (Low severity) was published Apr 13, 2021 pwweb/laravel-core (Composer)
Potential API key leak
GHSA-63rq-p8fp-524q (Moderate severity) was published Apr 13, 2021 sopel-modules.weather (pip)
Prototype Pollution in set-or-get
CVE-2021-25913 (Critical severity) was published Apr 12, 2021 set-or-get (npm)
Exposure of Resource to Wrong Sphere in valib
CVE-2019-10805 (Moderate severity) was published Apr 13, 2021 valib (npm)
Incorrect permission enforcement in UmbracoCms
CVE-2020-29454 (Moderate severity) was published Apr 13, 2021 UmbracoCms (NuGet)
OS Command Injection in giting
CVE-2019-10802 (High severity) was published Apr 13, 2021 seria-number (npm)
OS Command Injection in serial-number
CVE-2019-10804 (High severity) was published Apr 13, 2021 serial-number (npm)
Improper Authentication in react-adal
CVE-2020-7787 (High severity) was published Apr 13, 2021 react-adal (npm)
Improper Input Validation in sopel-plugins.channelmgnt
CVE-2021-21431 (High severity) was published Apr 9, 2021 sopel-plugins.channelmgnt (pip)
OS Command Injection in enpeem
CVE-2019-10801 (High severity) was published Apr 13, 2021 enpeem (npm)
ProTip! Advisories are also available from the GraphQL API