GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,722
Maven
5,000+
npm
4,329
NuGet
762
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,343 advisories
Filter by severity
Duplicate Advisory: Mautic has insufficient authentication in upgrade flow
High
GHSA-5hc5-fxr9-5frc
was published
for
mautic/core
(Composer)
Sep 19, 2024
•
withdrawn
Composer Remote Code Execution vulnerability via web-accessible composer.phar
High
CVE-2023-43655
was published
for
composer/composer
(Composer)
Sep 29, 2023
Composer has multiple command injections via malicious git/hg branch names
High
CVE-2024-35242
was published
for
composer/composer
(Composer)
Jun 10, 2024
Uvdesk remote code execution vulnerability
High
CVE-2023-0265
was published
for
uvdesk/community-skeleton
(Composer)
Apr 5, 2023
Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
High
CVE-2021-28583
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting (XSS) in the customer address upload feature
High
CVE-2021-21030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Signature verification bypass
High
CVE-2020-9588
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento authorization bypass vulnerability
High
CVE-2020-9587
was published
for
magento/community-edition
(Composer)
May 24, 2022
Unauthenticated crypto and weak IV in Magento\Framework\Encryption
High
CVE-2016-6485
was published
for
magento/community-edition
(Composer)
Nov 20, 2019
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8114
was published
for
magento/community-edition
(Composer)
May 24, 2022
Connect-CMS information that is restricted to viewing is visible
High
GHSA-2237-5r9w-vm8j
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
Cockpit Arbitrary File Upload
High
CVE-2025-1025
was published
for
cockpit-hq/cockpit
(Composer)
Feb 5, 2025
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
DevDojo Voyager vulnerable to path traversal
High
CVE-2024-55415
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
High
CVE-2023-30130
was published
for
craftcms/cms
(Composer)
May 12, 2023
Duplicate Advisory: openCart Server-Side Template Injection (SSTI) vulnerability
High
GHSA-j2v2-3784-vr44
was published
for
opencart/opencart
(Composer)
Dec 18, 2024
•
withdrawn
Uncontrolled Resource Consumption in moodle
High
CVE-2024-25978
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Cross-Site Request Forgery in moodle
High
CVE-2024-25982
was published
for
moodle/moodle
(Composer)
Feb 19, 2024
Authenticated arbitrary file deletion in YesWiki
High
CVE-2025-24019
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Authenticated Stored XSS in YesWiki
High
CVE-2025-24018
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Unauthenticated DOM Based XSS in YesWiki
High
CVE-2025-24017
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Dolibarr vulnerable to remote code execution via uppercase manipulation
High
CVE-2023-30253
was published
for
dolibarr/dolibarr
(Composer)
May 29, 2023
Laravel Framework RCE Vulnerability
High
CVE-2018-15133
was published
for
laravel/framework
(Composer)
May 14, 2022
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
Extension:TabberNeue vulnerable to Cross-site Scripting
High
CVE-2025-21612
was published
for
starcitizentools/tabber-neue
(Composer)
Jan 6, 2025
ProTip!
Advisories are also available from the
GraphQL API