The Wayback Machine - https://web.archive.org/web/20240105072143/https://github.com/advisories
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

15,688 advisories

view_component Cross-site Scripting vulnerability Moderate
CVE-2024-21636 was published for view_component (RubyGems) Jan 4, 2024
BlakeWilliams camertron
class.upload.php allows cross-site scripting attacks via uploaded files Moderate
CVE-2023-6551 was published for verot/class.upload.php (Composer) Jan 4, 2024
Froxlor username/surname AND company field Bypass High
CVE-2023-50256 was published for froxlor/froxlor (Composer) Jan 4, 2024
ahmedvienna
Ion Java StackOverflow vulnerability High
CVE-2024-21634 was published for com.amazon.ion:ion-java (Maven) Jan 3, 2024
Craft CMS Privilege Escalation Moderate
CVE-2024-21622 was published for craftcms/cms (Composer) Jan 3, 2024
johnax0
PrestaShop XSS can be stored in DB from "add a message form" in order detail page (FO) Moderate
CVE-2024-21628 was published for prestashop/prestashop (Composer) Jan 3, 2024
matthieu-rolland AureRita
boherm matks nicosomb
Rust EVM erroneousle handles `record_external_operation` error return Moderate
CVE-2024-21629 was published for evm (Rust) Jan 3, 2024
Omniauth::MicrosoftGraph Account takeover (nOAuth) High
CVE-2024-21632 was published for omniauth-microsoft_graph (RubyGems) Jan 3, 2024
Vapor contains an integer overflow in URI leading to potential host spoofing Moderate
CVE-2024-21631 was published for https://github.com/vapor/vapor (Swift) Jan 3, 2024
0xTim gwynne
baarde
PrestaShop some attribute not escaped in Validate::isCleanHTML method High
CVE-2024-21627 was published for prestashop/prestashop (Composer) Jan 3, 2024
Antonio-R1 antoniospataro
matthieu-rolland AureRita boherm matks
safe_pqc_kyber leaks parts of secret keys High
GHSA-p4v8-jgcv-9g75 was published for safe_pqc_kyber (Rust) Jan 3, 2024
User-provided environment values allow execution on macOS agents High
GHSA-vfxf-76hv-v4w4 was published for https://github.com/gravitational/teleport (Go) Jan 3, 2024
Tener jentfoo
SFTP is possible on the Proxy server for any user with SFTP access High
GHSA-c9v7-wmwj-vf6x was published for github.com/gravitational/teleport (Go) Jan 3, 2024
Tener
Teleport Access List owners can escalate their privileges Critical
GHSA-76cc-p55w-63g3 was published for github.com/gravitational/teleport (Go) Jan 3, 2024
Moaz219
Teleport Proxy and Teleport Agents: SSRF to arbitrary hosts is possible from low privileged users Critical
GHSA-hw4x-mcx5-9q36 was published for github.com/gravitational/teleport (Go) Jan 3, 2024
Tener espadolini
Arbitrary remote code execution within `wrangler dev` Workers sandbox Critical
CVE-2023-7080 was published for wrangler (npm) Jan 3, 2024
Lekensteyn
Arbitrary remote file read in Wrangler dev server Moderate
CVE-2023-7079 was published for wrangler (npm) Jan 3, 2024
Lekensteyn
The DES/3DES cipher was used as part of the TLS protocol by installation tools Low
GHSA-7xg2-83f8-39mr was published for github.com/karmada-io/karmada (Go) Jan 3, 2024
zhzhuang-zju yanfeng1992
Duplicate Advisory: Improper Handling of Exceptional Conditions in Newtonsoft.Json High
GHSA-8rfx-6mr3-5jh3 was published for Newtonsoft.Json (NuGet) Jan 3, 2024 withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE plugins Moderate
GHSA-wxj2-777f-vxmf was published for tinymce (npm) Jan 3, 2024 withdrawn
Duplicate Advisory: Denial of service in CBOR library High
GHSA-hf3r-vmrv-7w29 was published for PeterO.Cbor (NuGet) Jan 3, 2024 withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE Moderate
GHSA-q5pp-5q2h-g8rv was published for tinymce (npm) Jan 3, 2024 withdrawn
Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE Moderate
GHSA-gjhc-6xm7-mc8q was published for tinymce (npm) Jan 3, 2024 withdrawn
CubeFS leaks users key in logs Moderate
CVE-2023-46742 was published for github.com/cubefs/cubefs (Go) Jan 3, 2024
AdamKorcz
CubeFS leaks magic secret key when starting Blobstore access service Moderate
CVE-2023-46741 was published for github.com/cubefs/cubefs (Go) Jan 3, 2024
AdamKorcz
ProTip! Advisories are also available from the GraphQL API