GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,492
Maven
5,000+
npm
4,115
NuGet
735
pip
3,939
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,290 advisories
Filter by severity
Insufficient Session Expiration in Sylius
High
CVE-2022-24743
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
Stored Cross-site Scripting in grav
High
CVE-2022-0970
was published
for
getgrav/grav
(Composer)
Mar 16, 2022
Integer Overflow in microweber
High
CVE-2022-0968
was published
for
microweber/microweber
(Composer)
Mar 16, 2022
Denial of service in microweber
High
CVE-2022-0961
was published
for
microweber/microweber
(Composer)
Mar 16, 2022
NaN/INF in serverbound movement packets can crash clients and servers
High
GHSA-fm35-jgg3-3grx
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 18, 2022
Improperly checked metadata on tools/armour itemstacks received from the client
High
GHSA-46c5-pfj8-fv65
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 18, 2022
Insufficient Session Expiration in Admidio
High
CVE-2022-0991
was published
for
admidio/admidio
(Composer)
Mar 20, 2022
Exposure of Resource to Wrong Sphere in ThinkPHP Framework
High
CVE-2022-25481
was published
for
topthink/framework
(Composer)
Mar 22, 2022
Unrestricted Upload of File with Dangerous Type in ShowDoc
High
CVE-2022-1034
was published
for
showdoc/showdoc
(Composer)
Mar 23, 2022
Integer Overflow or Wraparound in Microweber
High
CVE-2022-1036
was published
for
microweber/microweber
(Composer)
Mar 23, 2022
SQL Injection in Fork CMS
High
CVE-2022-0153
was published
for
forkcms/forkcms
(Composer)
Mar 25, 2022
SQL Injection in Fork CMS
High
CVE-2022-1064
was published
for
forkcms/forkcms
(Composer)
Mar 26, 2022
SQL Injection in Yeswiki
High
CVE-2021-43091
was published
for
yeswiki/yeswiki
(Composer)
Mar 26, 2022
Arbitrary shell execution
High
GHSA-mhfv-8rc9-w38c
was published
for
squizlabs/php_codesniffer
(Composer)
Mar 26, 2022
Arbitrary shell execution
High
GHSA-3988-h75v-hwf6
was published
for
squizlabs/php_codesniffer
(Composer)
Mar 26, 2022
Parsedown Class-Name Injection
High
CVE-2019-10905
was published
for
erusev/parsedown
(Composer)
Mar 26, 2022
Symfony Http-Kernel has non-constant time comparison in UriSigner
High
CVE-2019-18887
was published
for
symfony/http-kernel
(Composer)
Mar 26, 2022
Path Traversal in ImpressCMS
High
CVE-2021-26601
was published
for
impresscms/impresscms
(Composer)
Mar 29, 2022
Path Traversal within joomla/archive tar class
High
CVE-2022-23793
was published
for
joomla/archive
(Composer)
Mar 31, 2022
Old sessions not blocked by login enable function in Snipe-IT
High
CVE-2022-1155
was published
for
snipe/snipe-it
(Composer)
Mar 31, 2022
Type Confusion in LiveHelperChat
High
CVE-2022-1176
was published
for
remdex/livehelperchat
(Composer)
Apr 1, 2022
Unrestricted Upload of File with Dangerous Type in WPanel 4
High
CVE-2021-34257
was published
for
wpanel/wpanel4-cms
(Composer)
Apr 1, 2022
Access Control vulnerability in Dolibarr
High
CVE-2021-37517
was published
for
dolibarr/dolibarr
(Composer)
Apr 1, 2022
ProTip!
Advisories are also available from the
GraphQL API