Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

128 advisories

Loading
In the Linux kernel, the following vulnerability has been resolved: mm: call the... High Unreviewed
CVE-2024-47745 was published Oct 21, 2024
In Gradio, the `enable_monitoring` flag set to `False` does not disable monitoring Low
CVE-2024-47168 was published for gradio (pip) Oct 10, 2024
ahpaleus Credited to ahpaleus and Vasco-jofra Vasco-jofra Vasco-jofra
btcd did not correctly re-implement Bitcoin Core's "FindAndDelete()" functionality High
CVE-2024-38365 was published for github.com/btcsuite/btcd (Go) Oct 10, 2024
darosior Credited to darosior and dergoegge dergoegge dergoegge
wasmtime has a runtime crash when combining tail calls with trapping imports Moderate
CVE-2024-47763 was published for wasmtime (Rust) Oct 9, 2024
alexcrichton Credited to alexcrichton and fitzgen fitzgen fitzgen
Denial of service in quinn-proto when using `Endpoint::retry()` High
CVE-2024-45311 was published for quinn-proto (Rust) Sep 3, 2024
finnbear Credited to finnbear and BiagioFesta BiagioFesta BiagioFesta
Keycloak's improper input validation allows using email as username Low
CVE-2021-3754 was published for org.keycloak:keycloak-services (Maven) Jun 12, 2024
Chetven Credited to Chetven
Contract balance not updating correctly after interchain transaction High
CVE-2024-37153 was published for github.com/evmos/evmos/v10 (Go) Jun 6, 2024
Vvaradinov Credited to Vvaradinov and EvmosDAO EvmosDAO EvmosDAO
In the Linux kernel, the following vulnerability has been resolved: net: USB: Fix wrong... Moderate Unreviewed
CVE-2023-52742 was published May 21, 2024
Requests `Session` object does not verify requests after making first request with verify=False Moderate
CVE-2024-35195 was published for requests (pip) May 20, 2024
mikeassel Credited to mikeassel, sigmavirus24, nateprewitt, and liiiiiiaduarte34-art sigmavirus24 sigmavirus24
nateprewitt nateprewitt liiiiiiaduarte34-art liiiiiiaduarte34-art
Tor Arti's STUB circuits incorrectly have a length of 2 High
CVE-2024-35312 was published for arti (Rust) May 18, 2024
eZ Platform Rules to disable executable access are ignored on Platform.sh (eZ Cloud) Moderate
GHSA-6xch-2vxx-5pvr was published for ezsystems/ezplatform (Composer) May 15, 2024
OpenZeppelin Contracts and Contracts Upgradeable duplicated execution of subcalls in v4.9.4 Moderate
CVE-2023-49798 was published for @openzeppelin/contracts (npm) Dec 12, 2023
Always incorrect control flow in github.com/mojocn/base64Captcha Moderate
CVE-2023-45292 was published for github.com/mojocn/base64Captcha (Go) Dec 12, 2023
Fiber unauthorized access vulnerability in `ctx.IsFromLocal()` Moderate
CVE-2023-41338 was published for github.com/gofiber/fiber (Go) Sep 8, 2023
schicho Credited to schicho, gaby, efectn, jozsefsallai, and ReneWerner87 gaby gaby
efectn efectn jozsefsallai jozsefsallai ReneWerner87 ReneWerner87
andreasdj Credited to andreasdj
Trigger `beforeFind` not invoked in internal query pipeline when fetching pointer High
CVE-2023-41058 was published for parse-server (npm) Sep 4, 2023
Moumouls Credited to Moumouls and mtrezza mtrezza mtrezza
ProTip! Advisories are also available from the GraphQL API