Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

19,477 advisories

Loading
Django denial of service via empty session record creation Moderate
CVE-2015-5963 was published for django (pip) May 17, 2022
MarkLee131
Plone Cross-site Scripting Vulnerability Moderate
CVE-2015-7316 was published for plone (pip) May 17, 2022
Plone unauthorized member addition vulnerability Moderate
CVE-2015-7315 was published for Products.CMFPlone (pip) May 17, 2022
Plone Header Injection High
CVE-2015-7318 was published for plone (pip) May 17, 2022
IPython vulnerable to cross site request forgery (CSRF) High
CVE-2015-5607 was published for ipython (pip) May 17, 2022
eGroupware Community Edition Stored XSS vulnerability Moderate
CVE-2017-14920 was published for egroupware/egroupware (Composer) May 17, 2022
Plone vulnerable to cross-site request forgery High
CVE-2015-7293 was published for Plone (pip) May 17, 2022
SaltStack Salt Authentication Bypass when using the local_batch client from salt-api High
CVE-2017-5192 was published for salt (pip) May 17, 2022
Apache Geode gfsh query vulnerability Moderate
CVE-2017-9794 was published for org.apache.geode:geode-core (Maven) May 17, 2022
Laravel Sensitive Data Exposure Moderate
CVE-2017-14775 was published for illuminate/auth (Composer) May 17, 2022
G-Rath
Improper Restriction of XML External Entity Reference in Jelly Critical
CVE-2017-12621 was published for commons-jelly:commons-jelly (Maven) May 17, 2022
Jenkins Docker Commons Plugin allows any user with Overall/Read permission to get list of valid credentials IDs Moderate
CVE-2017-1000094 was published for org.jenkins-ci.plugins:docker-commons (Maven) May 17, 2022
Jenkins Poll SCM Plugin vulnerable to Cross-Site Request Forgery High
CVE-2017-1000093 was published for org.jenkins-ci.plugins:pollscm (Maven) May 17, 2022
Cross-Site Request Forgery in Jenkins Git Plugin High
CVE-2017-1000092 was published for org.jenkins-ci.plugins:git (Maven) May 17, 2022
Jenkins GitHub Branch Source Plugin vulnerable to Cross-Site Request Forgery Moderate
CVE-2017-1000091 was published for org.jenkins-ci.plugins:github-branch-source (Maven) May 17, 2022
Exposure of Sensitive Information in Jenkins Datadog plugin Low
CVE-2017-1000114 was published for org.datadog.jenkins.plugins:datadog (Maven) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11797 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11801 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
Persistent XSS vulnerability in Jenkins OWASP Dependency-Check Plugin Moderate
CVE-2017-1000109 was published for org.jenkins-ci.plugins:dependency-check-jenkins-plugin (Maven) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11821 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11792 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11805 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11806 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11807 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ChakraCore RCE Vulnerability High
CVE-2017-11796 was published for Microsoft.ChakraCore (NuGet) May 17, 2022
ProTip! Advisories are also available from the GraphQL API