An open API service providing security vulnerability metadata for many open source software ecosystems.

Browse Security Advisories

High
about 12 hours ago

Argo CD Unauthenticated Remote DoS via malformed Azure DevOps git.push webhook GSA_kwCzR0hTQS1ncHg0LTM3ZzItYzhwds4ABMys

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
High
about 12 hours ago

argo-cd vulnerable unauthenticated DoS via malformed Gogs webhook payload GSA_kwCzR0hTQS13cDRwLTlweGgtY2d4Ms4ABMyX

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
High
about 12 hours ago

Unauthenticated argocd-server panic via a malicious Bitbucket-Server webhook payload GSA_kwCzR0hTQS1mOWdxLXBycmMtaHJoY84ABMyW

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
about 12 hours ago

Repository Credentials Race Condition Crashes Argo CD Server GSA_kwCzR0hTQS1nODhwLXI0MnItcHBwOc4ABMyV

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Critical
26 days ago

Argo CD's Project API Token Exposes Repository Credentials GSA_kwCzR0hTQS03ODZxLTloY2ctdjlmZs4ABLqo

go github.com/argoproj/argo-cd/v3, github.com/argoproj/argo-cd/v2
Critical
4 months ago

Argo CD allows cross-site scripting on repositories page GSA_kwCzR0hTQS0yaGo1LWc2NGctZnA2cM4ABIbo

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
over 1 year ago

Unauthenticated Access to sensitive settings in Argo CD GSA_kwCzR0hTQS04N3A5LXg3NWgtcDRqMs4AA8wy

go github.com/argoproj/argo-cd/v2/server
Critical
over 1 year ago

ArgoCD Vulnerable to Use of Risky or Missing Cryptographic Algorithms in Redis Cache GSA_kwCzR0hTQS05NzY2LTUyNzctajVocs4AA8aY

go github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2
Moderate
over 1 year ago

Users with `create` but not `override` privileges can perform local sync GSA_kwCzR0hTQS1nNjIzLWpjZ2ctbWhtbc4AA6Bz

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
High
over 1 year ago

github.com/argoproj/argo-cd Cross-Site Request Forgery vulnerability GSA_kwCzR0hTQS05Mm13LXEyNTYtNXZ3Z84AA4lC

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
about 2 years ago

Path traversal allows leaking out-of-bound Helm charts from Argo CD repo-server GSA_kwCzR0hTQS02anF3LWp3ZjUtcnA4aM4AA2HB

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
over 2 years ago

Argo CD authenticated but unauthorized users may enumerate Application names via the API GSA_kwCzR0hTQS0ycTVjLXF3OWMtZm12cc4AAyQf

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Critical
over 2 years ago

JWT audience claim is not verified GSA_kwCzR0hTQS1xOWhyLWo0cmYtOGZqY84AAxJD

go github.com/argoproj/argo-cd
Moderate
over 3 years ago

DoS through large manifest files in Argo CD GSA_kwCzR0hTQS1qaHFwLXZmNHctcnB3cc4AAs5e

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Moderate
over 3 years ago

Symlink following allows leaking out-of-bounds YAML files from Argo CD repo-server GSA_kwCzR0hTQS1xNHc1LTRncTItOTh2bc4AAs5a

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Critical
over 3 years ago

Argo CD's external URLs for Deployments can include JavaScript GSA_kwCzR0hTQS1oNHc5LTZ4NzgtOHZyas4AAs5Z

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
High
over 3 years ago

Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params GSA_kwCzR0hTQS0ybTdoLTg2cXEtZnA0ds4AAs5Y

go github.com/argoproj/argo-cd/v2, github.com/argoproj/argo-cd
Critical
over 3 years ago

Argo CD will blindly trust JWT claims if anonymous access is enabled GSA_kwCzR0hTQS1yNjQyLWd2OXAtMndqas4AAqwZ

go github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2
Moderate
over 3 years ago

Argo Exposure of Sensitive Information GSA_kwCzR0hTQS14ajd2LWM4MnctOTJxMs4AAkND

go github.com/argoproj/argo-cd
Moderate
over 3 years ago

Login screen allows message spoofing if SSO is enabled GSA_kwCzR0hTQS14bWc4LTk5cjgtamMyas4AAgd9

go github.com/argoproj/argo-cd, github.com/argoproj/argo-cd/v2
Moderate
almost 4 years ago

Observable Discrepancy in Argo MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZqNTQtY2pyeC14Njk2

go github.com/argoproj/argo-cd

Filter by Severity

Filter by Ecosystem

Filter by Package

tensorflow 432 moodle/moodle 418 tensorflow-cpu 409 tensorflow-gpu 405 magento/community-edition 264 Microsoft.ChakraCore 247 org.jenkins-ci.main:jenkins-core 242 typo3/cms 184 com.liferay.portal:release.portal.bom 146 org.apache.tomcat:tomcat 130 github.com/mattermost/mattermost/server/v8 129 pimcore/pimcore 120 com.liferay.portal:release.dxp.bom 117 dolibarr/dolibarr 116 Django 108 phpmyadmin/phpmyadmin 107 microweber/microweber 103 typo3/cms-core 103 magento/project-community-edition 98 drupal/core 98 silverstripe/framework 89 apache-airflow 86 librenms/librenms 83 drupal/drupal 74 thorsten/phpmyfaq 73 Plone 71 com.fasterxml.jackson.core:jackson-databind 69 github.com/usememos/memos 68 concrete5/concrete5 67 salt 65 ansible 63 apache-superset 61 actionpack 61 symfony/symfony 61 shopware/platform 58 org.apache.struts:struts2-core 56 github.com/grafana/grafana 56 mlflow 53 craftcms/cms 53 org.keycloak:keycloak-core 50 github.com/hashicorp/vault 49 nova 48 github.com/rancher/rancher 48 baserproject/basercms 47 mautic/core 47 shopware/core 46 nokogiri 46 gradio 44 vyper 44 org.xwiki.platform:xwiki-platform-oldcore 43 matrix-synapse 42 nilsteampassnet/teampass 42 rdiffweb 42 org.keycloak:keycloak-services 42 github.com/mattermost/mattermost-server 42 org.elasticsearch:elasticsearch 41 k8s.io/kubernetes 41 mantisbt/mantisbt 41 showdoc/showdoc 41 froxlor/froxlor 40 intelliants/subrion 40 picklescan 39 snipe/snipe-it 38 directus 38 org.apache.tomcat.embed:tomcat-embed-core 37 com.thoughtworks.xstream:xstream 37 github.com/mattermost/mattermost-server/v6 37 com.jfinal:jfinal 36 net.mingsoft:ms-mcms 36 github.com/argoproj/argo-cd/v2 36 moin 35 io.undertow:undertow-core 35 github.com/answerdev/answer 34 parse-server 33 org.jenkins-ci.plugins:script-security 33 zendframework/zendframework1 32 gogs.io/gogs 32 opencv-python 31 keystone 31 shopware/shopware 31 github.com/hashicorp/nomad 31 github.com/cilium/cilium 31 getgrav/grav 30 github.com/argoproj/argo-cd 30 opencv-contrib-python 30 rack 30 github.com/docker/docker 29 next 29 github.com/hashicorp/consul 29 contao/core-bundle 29 pillow 28 org.apache.solr:solr-core 28 electron 28 mediawiki/core 28 Pillow 28 plone 27 prestashop/prestashop 27 centreon/centreon 27 DotNetNuke.Core 27 org.opencms:opencms-core 27 org.springframework.security:spring-security-core 26 github.com/traefik/traefik/v2 25 vllm 25 open-webui 25 openssl-src 25 django 25 org.eclipse.jetty:jetty-server 25 rubygems-update 25 pocketmine/pocketmine-mp 25 org.keycloak:keycloak-parent 24 flowise 24 surrealdb 24 getkirby/cms 24 laravel/framework 23 org.apache.tomcat:tomcat-catalina 23 puppet 23 simplesamlphp/simplesamlphp 23 remdex/livehelperchat 23 grumpydictator/firefly-iii 23 pyload-ng 23 ckb 22 zendframework/zendframework 22 activerecord 22 tribalsystems/zenario 22 org.apache.openmeetings:openmeetings-parent 22 org.apache.nifi:nifi 21 github.com/goharbor/harbor 21 org.bouncycastle:bcprov-jdk15on 21 @openzeppelin/contracts-upgradeable 21 @openzeppelin/contracts 21 glance 21 org.xwiki.platform:xwiki-platform-web-templates 20 github.com/ethereum/go-ethereum 20 ethyca-fides 20 aim 20 wasmtime 20 typo3/cms-backend 20 funadmin/funadmin 20 cockpit-hq/cockpit 20 org.cloudfoundry.identity:cloudfoundry-identity-server 20 code.gitea.io/gitea 20 github.com/zitadel/zitadel 19 langchain 19 topthink/framework 19 deno 19 neutron 19 phpoffice/phpspreadsheet 19 transformers 19 contao/contao 19 helm.sh/helm/v3 19 forkcms/forkcms 18 org.apache.jspwiki:jspwiki-main 18 Microsoft.AspNetCore.App.Runtime.win-x86 18 golang.org/x/net 18 genix/cms 18 mindsdb 18 mercurial 18 com.vaadin:vaadin-bom 18 org.springframework:spring-core 18 Microsoft.AspNetCore.App.Runtime.win-x64 18 cobbler 18 ezsystems/ezpublish-kernel 17 Microsoft.AspNetCore.App.Runtime.win-arm 17 cryptography 17 Microsoft.AspNetCore.App.Runtime.linux-arm64 17 Microsoft.AspNetCore.App.Runtime.linux-arm 17 calibreweb 17 notebook 17 org.apache.geode:geode-core 17 OctoPrint 17 yetiforce/yetiforce-crm 17 github.com/openfga/openfga 17 org.apache.inlong:manager-pojo 17 cakephp/cakephp 17 francoisjacquet/rosariosis 17 opencart/opencart 17 openmage/magento-lts 17 paddlepaddle 16 org.apache.tomcat:tomcat-coyote 16 github.com/traefik/traefik/v3 16 org.apache.ranger:ranger 16 org.apache.dubbo:dubbo 16 phpbb/phpbb 16 Microsoft.AspNetCore.App.Runtime.linux-musl-arm64 16 sequelize 16 Microsoft.AspNetCore.App.Runtime.linux-musl-x64 16 rusqlite 16 tinymce 16 Microsoft.AspNetCore.App.Runtime.win-arm64 16 org.apache.activemq:activemq-client 16 lollms 16 october/system 16 ghost 16 PaddlePaddle 16 Microsoft.NetCore.App.Runtime.win-arm64 15 Microsoft.AspNetCore.App.Runtime.linux-x64 15 smarty/smarty 15 github.com/nats-io/nats-server/v2 15 undici 15 aiohttp 15

Filter by Repository

https://github.com/tensorflow/tensorflow 433 https://github.com/moodle/moodle 243 https://github.com/xwiki/xwiki-platform 221 https://github.com/chakra-core/ChakraCore 214 https://github.com/jenkinsci/jenkins 178 https://github.com/liferay/liferay-portal 138 https://github.com/django/django 117 https://github.com/pimcore/pimcore 116 https://github.com/apache/tomcat 114 https://github.com/apache/airflow 104 https://github.com/TYPO3/typo3 94 https://github.com/microweber/microweber 90 https://github.com/keycloak/keycloak 86 https://github.com/librenms/librenms 74 https://github.com/FasterXML/jackson-databind 70 https://github.com/rails/rails 70 https://github.com/thorsten/phpmyfaq 69 https://github.com/usememos/memos 68 https://github.com/silverstripe/silverstripe-framework 68 https://github.com/kubernetes/kubernetes 66 https://github.com/symfony/symfony 64 https://github.com/Dolibarr/dolibarr 60 https://github.com/ansible/ansible 59 https://github.com/python-pillow/Pillow 52 https://github.com/spring-projects/spring-framework 51 https://github.com/argoproj/argo-cd 50 https://github.com/grafana/grafana 47 https://github.com/apache/struts 47 https://github.com/mautic/mautic 46 https://github.com/phpmyadmin/phpmyadmin 45 https://github.com/vyperlang/vyper 44 https://github.com/rancher/rancher 44 https://github.com/concretecms/concretecms 44 https://github.com/shopware/platform 43 https://github.com/saltstack/salt 42 https://github.com/ikus060/rdiffweb 42 https://github.com/directus/directus 41 https://github.com/craftcms/cms 41 https://github.com/star7th/showdoc 39 https://github.com/mmaitre314/picklescan 39 https://github.com/mattermost/mattermost 39 https://github.com/mantisbt/mantisbt 38 https://github.com/openstack/nova 38 https://github.com/gradio-app/gradio 38 https://github.com/magento/magento2 38 https://github.com/x-stream/xstream 37 https://github.com/dotnet/runtime 37 https://github.com/plone/Products.CMFPlone 37 https://github.com/octobercms/october 36 https://github.com/umbraco/Umbraco-CMS 35 https://github.com/sparklemotion/nokogiri 35 https://github.com/mlflow/mlflow 35 https://github.com/shopware/shopware 35 https://github.com/answerdev/answer 34 https://github.com/apache/activemq 34 https://github.com/parse-community/parse-server 33 https://github.com/go-gitea/gitea 32 https://github.com/opencv/opencv 32 https://github.com/matrix-org/synapse 32 https://github.com/apache/inlong 31 https://github.com/PaddlePaddle/Paddle 31 https://github.com/cilium/cilium 31 https://github.com/contao/contao 30 https://github.com/snipe/snipe-it 30 https://github.com/electron/electron 28 https://github.com/openstack/keystone 28 https://github.com/gogs/gogs 28 https://github.com/CVEProject/cvelist 28 https://github.com/geoserver/geoserver 26 https://github.com/froxlor/froxlor 26 https://github.com/github/advisory-database 26 https://github.com/apache/nifi 26 https://github.com/netty/netty 26 https://github.com/baserproject/basercms 26 https://github.com/surrealdb/surrealdb 25 https://github.com/pmmp/PocketMine-MP 25 https://github.com/traefik/traefik 25 https://github.com/vercel/next.js 25 https://github.com/strapi/strapi 25 https://github.com/rack/rack 24 https://github.com/langchain-ai/langchain 24 https://github.com/getgrav/grav 24 https://github.com/apache/cxf 24 https://github.com/bcgit/bc-java 24 https://github.com/run-llama/llama_index 23 https://github.com/eclipse/jetty.project 23 https://github.com/livehelperchat/livehelperchat 23 https://github.com/moby/moby 23 https://github.com/firefly-iii/firefly-iii 23 https://github.com/TYPO3/TYPO3.CMS 23 https://github.com/pyload/pyload 23 https://github.com/PrestaShop/PrestaShop 23 https://github.com/nilsteampassnet/TeamPass 23 https://github.com/hashicorp/consul 22 https://github.com/bytecodealliance/wasmtime 22 https://github.com/getkirby/kirby 22 https://github.com/jenkinsci/script-security-plugin 22 https://github.com/vllm-project/vllm 22 https://github.com/nervosnetwork/ckb 22 https://github.com/denoland/deno 22 https://github.com/PHPOffice/PhpSpreadsheet 22 https://github.com/helm/helm 22 https://github.com/zitadel/zitadel 22 https://github.com/OpenZeppelin/openzeppelin-contracts 21 https://github.com/goharbor/harbor 21 https://github.com/laravel/framework 21 https://github.com/undertow-io/undertow 21 https://github.com/ethyca/fides 20 https://github.com/simplesamlphp/simplesamlphp 20 https://github.com/funadmin/funadmin 20 https://github.com/jeecgboot/jeecg-boot 20 https://github.com/dnnsoftware/Dnn.Platform 20 https://github.com/FlowiseAI/Flowise 20 https://github.com/OpenNMS/opennms 20 https://github.com/nilsteampassnet/teampass 19 https://github.com/backstage/backstage 19 https://github.com/alkacon/opencms-core 19 https://github.com/TYPO3-CMS/core 19 https://github.com/opencast/opencast 19 https://github.com/hashicorp/vault 19 https://github.com/intelliants/subrion 19 https://github.com/cloudfoundry/uaa 19 https://github.com/huggingface/transformers 19 https://github.com/vaadin/platform 18 https://github.com/apache/camel 18 https://github.com/rubygems/rubygems 18 https://github.com/ethereum/go-ethereum 17 https://github.com/vantage6/vantage6 17 https://github.com/liufee/cms 17 https://github.com/OpenMage/magento-lts 17 https://github.com/openfga/openfga 17 https://github.com/containerd/containerd 17 https://github.com/mindsdb/mindsdb 17 https://github.com/pyca/cryptography 16 https://github.com/sequelize/sequelize 16 https://github.com/forkcms/forkcms 16 https://github.com/rusqlite/rusqlite 16 https://github.com/yetiforcecompany/yetiforcecrm 16 https://github.com/hashicorp/nomad 16 https://github.com/tinymce/tinymce 16 https://github.com/quarkusio/quarkus 16 https://github.com/etcd-io/etcd 16 https://github.com/xuxueli/xxl-job 15 https://github.com/drupal/core 15 https://github.com/cobbler/cobbler 15 https://github.com/MobSF/Mobile-Security-Framework-MobSF 15 https://github.com/puppetlabs/puppet 15 https://github.com/ckeditor/ckeditor4 15 https://github.com/vitejs/vite 15 https://github.com/PHPMailer/PHPMailer 15 https://github.com/nodejs/undici 15 https://github.com/dotnet/aspnetcore 15 https://github.com/OPCFoundation/UA-.NETStandard 15 https://github.com/decidim/decidim 15 https://github.com/aio-libs/aiohttp 15 https://github.com/dompdf/dompdf 15 https://github.com/centreon/centreon 15 https://github.com/containers/podman 15 https://github.com/zendframework/zendframework 15 https://github.com/cockpit-hq/cockpit 14 https://github.com/rails/rails-html-sanitizer 14 https://github.com/apache/kylin 14 https://github.com/apache/superset 14 https://github.com/pgadmin-org/pgadmin4 14 https://github.com/publify/publify 14 https://github.com/urllib3/urllib3 14 https://github.com/dpgaspar/Flask-AppBuilder 14 https://github.com/twisted/twisted 14 https://github.com/janeczku/calibre-web 14 https://github.com/pimcore/admin-ui-classic-bundle 14 https://github.com/Graylog2/graylog2-server 14 https://github.com/spring-projects/spring-security 14 https://github.com/cosmos/cosmos-sdk 14 https://github.com/golang/go 14 https://github.com/apache/zeppelin 14 https://github.com/thorsten/phpMyFAQ 14 https://github.com/TryGhost/Ghost 14 https://github.com/laurent22/joplin 13 https://github.com/modoboa/modoboa 13 https://github.com/apache/dolphinscheduler 13 https://github.com/ming-soft/MCMS 13 https://github.com/opencontainers/runc 13 https://github.com/dromara/hutool 13 https://github.com/1Panel-dev/1Panel 13 https://github.com/swagger-api/swagger-ui 13 https://github.com/OpenRefine/OpenRefine 13 https://github.com/getsentry/sentry 12 https://github.com/wagtail/wagtail 12 https://github.com/openstack/glance 12 https://github.com/matrix-org/matrix-js-sdk 12 https://github.com/puma/puma 12 https://github.com/ImageMagick/ImageMagick 12 https://github.com/smarty-php/smarty 12 https://github.com/codeigniter4/CodeIgniter4 12 https://github.com/patriksimek/vm2 12 https://github.com/centreon/centreon-archived 12 https://github.com/nautobot/nautobot 12 https://github.com/yiisoft/yii2 12 https://github.com/NodeBB/NodeBB 12