GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,887 advisories
Filter by severity
Cross-Site Request Forgery in firefly-iii
Moderate
CVE-2021-3819
was published
for
grumpydictator/firefly-iii
(Composer)
Sep 29, 2021
File reference keys leads to incorrect hashes on HMAC algorithms
Moderate
CVE-2021-41106
was published
for
lcobucci/jwt
(Composer)
Sep 29, 2021
Cross-site Scripting in yourls
Moderate
CVE-2021-3783
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
Cross-site Scripting in yourls
Moderate
CVE-2021-3785
was published
for
yourls/yourls
(Composer)
Sep 20, 2021
Observable Response Discrepancy in Lost Password Service
Moderate
CVE-2021-39189
was published
for
pimcore/pimcore
(Composer)
Sep 20, 2021
Cross-site scripting in ICEcoder
Moderate
CVE-2021-32106
was published
for
icecoder/icecoder
(Composer)
Sep 9, 2021
Cross-site Scripting in LibreNMS
Moderate
CVE-2021-31274
was published
for
librenms/librenms
(Composer)
Sep 9, 2021
Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2021-32716
was published
for
shopware/platform
(Composer)
Sep 8, 2021
Cross-site scripting
Moderate
CVE-2021-32713
was published
for
shopware/shopware
(Composer)
Sep 8, 2021
Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2021-32712
was published
for
shopware/shopware
(Composer)
Sep 8, 2021
Cross-site scripting in LavaLite-CMS
Moderate
CVE-2020-23700
was published
for
lavalite/cms
(Composer)
Sep 8, 2021
CSRF token exposure in TYPO3 extension
Moderate
CVE-2021-36793
was published
for
lms/routes
(Composer)
Sep 2, 2021
Use of Cryptographically Weak Pseudo-Random Number Generator in showdoc
Moderate
CVE-2021-3678
was published
for
showdoc/showdoc
(Composer)
Sep 2, 2021
XSS vulnerability on password reset page
Moderate
CVE-2021-27909
was published
for
mautic/core
(Composer)
Sep 1, 2021
Cross-site Scripting in the femanager TYPO3 extension
Moderate
CVE-2021-36787
was published
for
in2code/femanager
(Composer)
Sep 1, 2021
Cross-site Scripting in the yoast_seo TYPO3 extension
Moderate
CVE-2021-36788
was published
for
yoast-seo-for-typo3/yoast_seo
(Composer)
Sep 1, 2021
Use of Cryptographically Weak Pseudo-Random Number Generator in yiisoft/yii2-dev
Moderate
CVE-2021-3692
was published
for
yiisoft/yii2-dev
(Composer)
Sep 1, 2021
Cross Site Scripting in Subrion CMS
Moderate
CVE-2020-22392
was published
for
intelliants/subrion
(Composer)
Sep 1, 2021
Inadequate Encryption Strength in showdoc
Moderate
CVE-2021-3680
was published
for
showdoc/showdoc
(Composer)
Sep 1, 2021
Cross-site Scripting in TYPO3 extension
Moderate
CVE-2021-36785
was published
for
miniorange/miniorange-saml
(Composer)
Aug 30, 2021
Cross-site scripting in imgURL
Moderate
CVE-2021-38713
was published
for
helloxz/imgurl
(Composer)
Aug 30, 2021
Cross-site scripting in feehicms
Moderate
CVE-2020-19709
was published
for
feehi/feehicms
(Composer)
Aug 30, 2021
Improper Restriction of Rendered UI Layers or Frames in yourls
Moderate
CVE-2021-3734
was published
for
yourls/yourls
(Composer)
Aug 30, 2021
Insecure direct object reference of log files of the Import/Export feature
Moderate
CVE-2021-37709
was published
for
shopware/core
(Composer)
Aug 30, 2021
ProTip!
Advisories are also available from the
GraphQL API