Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,887 advisories

Loading
EC-CUBE Improper access control in Management screen Moderate
CVE-2021-20841 was published for ec-cube/ec-cube (Composer) Nov 25, 2021
CSV Injection in symfony/serializer Moderate
CVE-2021-41270 was published for symfony/serializer (Composer) Nov 24, 2021
jakeBarwell jderusse
Credited to jakeBarwell and jderusse
Cookie persistence after password changes in symfony/security-bundle Moderate
CVE-2021-41268 was published for symfony/security-bundle (Composer) Nov 24, 2021
thibaut-decherit wouterj
Credited to thibaut-decherit and wouterj
Webcache Poisoning in symfony/http-kernel Moderate
CVE-2021-41267 was published for symfony/http-kernel (Composer) Nov 24, 2021
jderusse shyim
Credited to jderusse and shyim
Server-Side Request Forgery in Concrete CMS Moderate
CVE-2021-22970 was published for concrete5/core (Composer) Nov 23, 2021
Server-Side Request Forgery in Concrete CMS Moderate
CVE-2021-22969 was published for concrete5/core (Composer) Nov 23, 2021
Password exposure in concrete5/core Moderate
CVE-2021-22951 was published for concrete5/core (Composer) Nov 23, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3976 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3963 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3957 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Exposure of sensitive information in concrete5/core Moderate
CVE-2021-22967 was published for concrete5/core (Composer) Nov 23, 2021
Cross-site Scripting in moodle Moderate
CVE-2021-43558 was published for moodle/moodle (Composer) Nov 23, 2021
The disqualify lead action may be executed without CSRF token check Moderate
CVE-2021-39198 was published for oro/crm (Composer) Nov 19, 2021
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys Moderate
CVE-2021-41273 was published for pterodactyl/panel (Composer) Nov 18, 2021
Haxatron
Credited to Haxatron
Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content. Moderate
CVE-2021-43617 was published for laravel/framework (Composer) Nov 16, 2021 withdrawn
Cross-site scripting (XSS) from image block content in the site frontend Moderate
CVE-2021-41258 was published for getkirby/cms (Composer) Nov 16, 2021
azrultech
Credited to azrultech
Cross-site scripting (XSS) from writer field content in the site frontend Moderate
CVE-2021-41252 was published for getkirby/cms (Composer) Nov 16, 2021
azrultech
Credited to azrultech
twill is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3932 was published for area17/twill (Composer) Nov 15, 2021
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3931 was published for snipe/snipe-it (Composer) Nov 15, 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3921 was published for grumpydictator/firefly-iii (Composer) Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3775 was published for showdoc/showdoc (Composer) Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3683 was published for showdoc/showdoc (Composer) Nov 15, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3776 was published for showdoc/showdoc (Composer) Nov 15, 2021
Cross-site Scripting in pegasus/google-for-jobs Moderate
CVE-2021-43561 was published for pegasus/google-for-jobs (Composer) Nov 15, 2021
Cross-site Scripting in LibreNMS Moderate
CVE-2021-43324 was published for librenms/librenms (Composer) Nov 8, 2021
ProTip! Advisories are also available from the GraphQL API