Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

17 advisories

Loading
jQuery-Upload-File XSS in fileNameStr Moderate
CVE-2021-37504 was published for jquery-file-upload (npm) Feb 26, 2022
anonymous4ACL24
CherryPy Malicious cookies allow access to files outside the session directory High
CVE-2008-0252 was published for cherrypy (pip) May 1, 2022
anonymous4ACL24
Roundup xml-rpc server improper check of property permissions Moderate
CVE-2008-1475 was published for roundup (pip) May 1, 2022
anonymous4ACL24
Roundup vulnerability related to Cross-site scripting (XSS) Moderate
CVE-2008-1474 was published for roundup (pip) May 1, 2022
anonymous4ACL24
Zope Object Database (ZODB) Authentication bypass in ZEO storage servers High
CVE-2009-0669 was published for ZODB3 (pip) May 2, 2022
anonymous4ACL24
Roundup Improper Access Control Moderate
CVE-2009-2737 was published for Roundup (pip) May 2, 2022
anonymous4ACL24
Buildbot Cross-site scripting (XSS) vulnerability Moderate
CVE-2009-2959 was published for buildbot (pip) May 2, 2022
anonymous4ACL24
Buildbot vulnerable to cross-site scripting Moderate
CVE-2009-2967 was published for buildbot (pip) May 2, 2022
anonymous4ACL24
MoinMoin Exposure of Sensitive Disclosure when GATEWAY_INTERFACE variable is set Moderate
CVE-2010-0667 was published for moin (pip) May 2, 2022
anonymous4ACL24
jplayer Cross Site Scripting vulnerability Moderate
CVE-2013-2022 was published for jplayer (npm) May 17, 2022
anonymous4ACL24
MediaWiki makeCollapsible allows applying event handler to any CSS selector Moderate
CVE-2020-10960 was published for mediawiki/core (Composer) May 24, 2022
anonymous4ACL24
HashiCorp Consul does not properly validate node or segment names prior to usage in JWT claim assertions High
CVE-2021-41803 was published for github.com/hashicorp/consul (Go) Sep 25, 2022
anonymous4ACL24
MooTools Regular Expression Denial of Service High
CVE-2021-32821 was published for mootools (npm) Jan 3, 2023
anonymous4ACL24
Nomad Caller ACL Token’s Secret ID is Exposed to Sentinel Low
CVE-2023-3299 was published for github.com/hashicorp/nomad (Go) Jul 20, 2023
anonymous4ACL24
Nomad ACL Policies without Label are Applied to Unexpected Resources Moderate
CVE-2023-3072 was published for github.com/hashicorp/nomad (Go) Jul 20, 2023
anonymous4ACL24
Nomad Search API Leaks Information About CSI Plugins Moderate
CVE-2023-3300 was published for github.com/hashicorp/nomad (Go) Jul 20, 2023
anonymous4ACL24
Consul JWT Auth in L7 Intentions Allow for Mismatched Service Identity and JWT Providers High
CVE-2023-3518 was published for github.com/hashicorp/consul (Go) Aug 9, 2023
anonymous4ACL24
ProTip! Advisories are also available from the GraphQL API