Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

39 advisories

Loading
alchemist.vim vulnerable to remote code execution Critical
CVE-2017-1000212 was published for alchemist.vim (Erlang) May 13, 2022
Hex authenticity of signed packages not validated High
CVE-2019-1000013 was published for hex_core (Erlang) May 13, 2022
maennchen
Credited to maennchen
Inline DTD allows XML bomb attack High
CVE-2019-15160 was published for sweet_xml (Erlang) Apr 12, 2022
Denial of service Moderate
CVE-2019-16764 was published for pow_assent (Erlang) Apr 12, 2022
Session fixation Moderate
CVE-2020-5205 was published for pow (Erlang) Apr 12, 2022
Header Injection Moderate
CVE-2018-1000883 was published for plug (Erlang) Apr 12, 2022
Arbitrary Code Execution in Cookie Serialization High
CVE-2017-1000053 was published for plug (Erlang) Apr 12, 2022
Null Byte Injection in Plug.Static High
CVE-2017-1000052 was published for plug (Erlang) Apr 12, 2022
Cross-site Scripting in xain Moderate
CVE-2018-20302 was published for xain (Erlang) Apr 12, 2022
Phoenix Arbitrary URL Redirect Moderate
CVE-2017-1000163 was published for phoenix (Erlang) Apr 12, 2022
XSS in HEEx class attributes Moderate
GHSA-j3gg-r6gp-95q2 was published for phoenix_html (Erlang) Apr 12, 2022
Missing `is_nil` requirement Moderate
GHSA-2xxx-fhc8-9qvq was published for ecto (Erlang) Apr 12, 2022
Remote Code Execution in paginator Critical
CVE-2020-15150 was published for paginator (Erlang) Apr 12, 2022
p-
Credited to p-
Permissive parameters and privilege escalation Moderate
CVE-2018-20301 was published for coherence (Erlang) Feb 10, 2022
ProTip! Advisories are also available from the GraphQL API