GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,868
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,117
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,780 advisories
Filter by severity
CKEditor 4 vulnerabilities in versions <4.16.1
Moderate
GHSA-cfcv-q4qq-2ph4
was published
for
pimcore/pimcore
(Composer)
Aug 23, 2021
PHP file inclusion via insert tags
Moderate
CVE-2021-37626
was published
for
contao/contao
(Composer)
Aug 23, 2021
Cross-Site Scripting via Rich-Text Content
Moderate
CVE-2021-32768
was published
for
typo3/cms
(Composer)
Aug 19, 2021
Improper Access Control in Dolibarr
Moderate
CVE-2021-25954
was published
for
dolibarr/dolibarr
(Composer)
Aug 11, 2021
Cross Site Scripting in LavaLite CMS
Moderate
CVE-2020-23234
was published
for
lavalite/cms
(Composer)
Aug 9, 2021
No Restriction of Excessive Authentication Attempts in Firefly III
Moderate
CVE-2021-3663
was published
for
grumpydictator/firefly-iii
(Composer)
Aug 9, 2021
Incorrect Authorization in TYPO3 extension
Moderate
CVE-2020-25025
was published
for
localizationteam/l10nmgr
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12700
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12698
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Information Disclosure in User Authentication
Moderate
CVE-2021-32767
was published
for
typo3/cms
(Composer)
Jul 26, 2021
Cross-Site Scripting in Backend Grid View
Moderate
CVE-2021-32669
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Query Generator & Query View
Moderate
CVE-2021-32668
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Page Preview
Moderate
CVE-2021-32667
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-site Scripting in Froala WYSIWYG Editor
Moderate
CVE-2021-28114
was published
for
froala/wysiwyg-editor
(Composer)
Jul 19, 2021
Craft CMS Cross-site Scripting Vulnerability
Moderate
CVE-2021-27902
was published
for
craftcms/cms
(Composer)
Jul 2, 2021
XSS Injection in Media Collection Title was possible
Moderate
CVE-2021-32737
was published
for
sulu/sulu
(Composer)
Jul 2, 2021
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
Missing Authentication for Critical Function
Moderate
CVE-2021-32709
was published
for
shopware/platform
(Composer)
Jun 29, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API
Moderate
CVE-2021-32720
was published
for
sylius/sylius
(Composer)
Jun 29, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api
Moderate
GHSA-gpmh-g94g-qrhr
was published
for
shopware/core
(Composer)
Jun 28, 2021
Canceling of orders not related to the logged-in user
Moderate
GHSA-wq3r-jwrq-xg6w
was published
for
shopware/core
(Composer)
Jun 28, 2021
Cross-site Scripting in yii2cmf
Moderate
CVE-2018-10704
was published
for
yidashi/yii2cmf
(Composer)
Jun 22, 2021
Session Fixation in Subrion CMS
Moderate
CVE-2020-12467
was published
for
intelliants/subrion
(Composer)
Jun 22, 2021
Cross-site scripting in PageKit
Moderate
CVE-2021-32245
was published
for
pagekit/pagekit
(Composer)
Jun 22, 2021
ProTip!
Advisories are also available from the
GraphQL API