GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,783
Erlang
36
GitHub Actions
29
Go
2,355
Maven
5,000+
npm
3,978
NuGet
720
pip
3,774
Pub
12
RubyGems
923
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
318 advisories
Filter by severity
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows...
Low
Unreviewed
CVE-2024-5905
was published
Jun 12, 2024
TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in...
Moderate
Unreviewed
CVE-2024-37661
was published
Jun 17, 2024
Lack of validation of origin in federation API in Conduit, allowing any remote server to...
Moderate
Unreviewed
CVE-2024-6301
was published
Jun 25, 2024
Gin mishandles a wildcard at the end of an origin string
Critical
CVE-2019-25211
was published
for
github.com/gin-contrib/cors
(Go)
Jun 29, 2024
Origin Validation Error in GitHub repository stitionai/devika prior to -.
High
Unreviewed
CVE-2024-5549
was published
Jul 9, 2024
There is a permissions and access control vulnerability in ZXCLOUD IRAI.An attacker can elevate...
Moderate
Unreviewed
CVE-2024-22062
was published
Jul 9, 2024
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e...
High
Unreviewed
CVE-2024-41143
was published
Jul 29, 2024
Mattermost allows remote actor to set arbitrary RemoteId values for synced users
Moderate
CVE-2024-41926
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Aug 1, 2024
Flowise Cors Misconfiguration in packages/server/src/index.ts
High
CVE-2024-36421
was published
for
flowise
(npm)
Aug 5, 2024
While copying individual autoupdater log files, reparse point check was missing which could...
High
Unreviewed
CVE-2024-23458
was published
Aug 6, 2024
Gnuboard g6 6.0.7 is vulnerable to Session hijacking due to a CORS misconfiguration.
Critical
Unreviewed
CVE-2024-41475
was published
Aug 12, 2024
Insufficient policy enforcement in Data Transfer in Google Chrome prior to 128.0.6613.84 allowed...
Moderate
Unreviewed
CVE-2024-7978
was published
Aug 21, 2024
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of...
Moderate
Unreviewed
CVE-2024-44187
was published
Sep 17, 2024
A compromised content process could have allowed for the arbitrary loading of cross-origin pages....
Critical
Unreviewed
CVE-2024-9392
was published
Oct 1, 2024
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under...
High
Unreviewed
CVE-2024-9393
was published
Oct 1, 2024
Gradios's CORS origin validation is not performed when the request has a cookie
High
CVE-2024-47084
was published
for
gradio
(pip)
Oct 10, 2024
Gradio's CORS origin validation accepts the null origin
Moderate
CVE-2024-47165
was published
for
gradio
(pip)
Oct 10, 2024
Incorrect access control in Mirotalk before commit 9de226 allows attackers to arbitrarily change...
High
Unreviewed
CVE-2024-44734
was published
Oct 11, 2024
The origin of an external protocol handler prompt could have been obscured using a data: URL...
Moderate
Unreviewed
CVE-2024-10460
was published
Oct 29, 2024
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal...
High
Unreviewed
CVE-2024-6674
was published
Oct 29, 2024
Origin Validation Error vulnerability in Dataprom Informatics Personnel Attendance Control...
High
Unreviewed
CVE-2024-10534
was published
Nov 15, 2024
lilishop <=4.2.4 is vulnerable to Incorrect Access Control, which can allow attackers to obtain...
High
Unreviewed
CVE-2024-50654
was published
Nov 15, 2024
An issue in kodbox v.1.52.04 and before allows a remote attacker to obtain sensitive information...
Moderate
Unreviewed
CVE-2024-51037
was published
Nov 15, 2024
An issue in Instrument Cluster KIA Seltos Software v1.0, Hardware v1.0 allows attackers to cause...
Moderate
Unreviewed
CVE-2024-51072
was published
Nov 22, 2024
MSA FieldServer Gateway 5.0.0 through 6.5.2 allows cross-origin WebSocket hijacking.
Moderate
Unreviewed
CVE-2024-45495
was published
Nov 29, 2024
ProTip!
Advisories are also available from the
GraphQL API