Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

23 advisories

Loading
pnpm: Repository-controlled configDependencies can select a pacquet native install engine High
CVE-2026-55697 was published for pnpm (npm) Jun 26, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment High
GHSA-w7pm-9g55-mxfm was published for stigmem-node (pip) May 29, 2026
amwhoi Credited to amwhoi
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) High
CVE-2026-42575 was published for chainguard.dev/apko (Go) May 4, 2026
1seal Credited to 1seal and antitree antitree antitree
Axios npm Supply Chain Incident Impacting @usebruno/cli Critical
CVE-2026-34841 was published for @usebruno/cli (npm) Apr 2, 2026
ZeroXJacks Credited to ZeroXJacks
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies High
CVE-2025-69263 was published for pnpm (npm) Jan 7, 2026
orenyomtov Credited to orenyomtov
Gradio lacks integrity checking on the downloaded FRP client High
CVE-2024-47867 was published for gradio (pip) Oct 10, 2024
ahpaleus Credited to ahpaleus and Vasco-jofra Vasco-jofra Vasco-jofra
WP Crontrol vulnerable to possible RCE when combined with a pre-condition High
CVE-2024-28850 was published for johnbillion/wp-crontrol (Composer) Mar 25, 2024
johnbillion Credited to johnbillion and calvinalkan calvinalkan calvinalkan
Artifact Hub has Incorrect Docker Hub registry check Moderate
CVE-2023-45821 was published for github.com/artifacthub/hub (Go) Oct 19, 2023
dejanzelic Credited to dejanzelic
Gin Web Framework does not properly sanitize filename parameter of Context.FileAttachment function Moderate
CVE-2023-29401 was published for github.com/gin-gonic/gin (Go) May 12, 2023
adam-baxter_cbais Credited to adam-baxter_cbais, godwhoa, jetzlstorfer, danieljmt, and raph6 godwhoa godwhoa
jetzlstorfer jetzlstorfer danieljmt danieljmt raph6 raph6
RuoYi vulnerable to arbitrary file download High
CVE-2023-27025 was published for com.ruoyi:ruoyi (Maven) Apr 2, 2023
achibear Credited to achibear
Sinatra vulnerable to Reflected File Download attack High
CVE-2022-45442 was published for sinatra (RubyGems) Nov 30, 2022
motoyasu-saburi Credited to motoyasu-saburi
Django vulnerable to Reflected File Download attack High
CVE-2022-36359 was published for Django (pip) Aug 11, 2022
sunSUNQ Credited to sunSUNQ, levpachmanov, and G-Rath levpachmanov levpachmanov
G-Rath G-Rath
Jenkins Plugin Installation Manager Tool did not verify plugin downloads Critical
CVE-2020-2320 was published for io.jenkins.plugin-management:plugin-management-parent-pom (Maven) May 24, 2022
westonsteimel Credited to westonsteimel, NotMyFault, and tdunlap607 NotMyFault NotMyFault
tdunlap607 tdunlap607
Cargo prior to Rust 1.26.0 may download the wrong dependency High
CVE-2019-16760 was published for cargo (Rust) May 24, 2022
Incorrect Resource Transfer Between Spheres in Grails High
CVE-2019-12728 was published for org.grails:grails-core (Maven) May 24, 2022
Eclipse Vorto resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS High
CVE-2019-10248 was published for org.eclipse.vorto:org.eclipse.vorto.core (Maven) May 24, 2022
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application High
CVE-2020-5398 was published for org.springframework:spring-webflux (Maven) Jan 21, 2020
briandealwis Credited to briandealwis and sunSUNQ sunSUNQ sunSUNQ
High severity vulnerability that affects generator-jhipster High
GHSA-mc84-xr9p-938r was published for generator-jhipster (npm) Sep 23, 2019
ProTip! Advisories are also available from the GraphQL API