GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,113
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,867 advisories
Filter by severity
SQL injection in pagekit/pagekit
Critical
CVE-2021-44135
was published
for
pagekit/pagekit
(Composer)
Apr 2, 2022
Type Confusion in LiveHelperChat
High
CVE-2022-1176
was published
for
remdex/livehelperchat
(Composer)
Apr 1, 2022
Cross-site Scripting in craftcms/cms
Moderate
CVE-2022-28378
was published
for
craftcms/cms
(Composer)
Apr 4, 2022
Unrestricted Upload of File with Dangerous Type in WPanel 4
High
CVE-2021-34257
was published
for
wpanel/wpanel4-cms
(Composer)
Apr 1, 2022
Open redirect in wwbn/avideo
Moderate
CVE-2022-27463
was published
for
wwbn/avideo
(Composer)
Apr 6, 2022
Files or Directories Accessible to External Parties in Adminer
High
CVE-2021-43008
was published
for
vrana/adminer
(Composer)
Apr 6, 2022
Remote code execution in Subrion
High
CVE-2021-43464
was published
for
intelliants/subrion
(Composer)
Apr 5, 2022
Server side request forgery in LiveHelperChat
High
CVE-2022-1213
was published
for
remdex/livehelperchat
(Composer)
Apr 6, 2022
Cross-site Scripting in TastyIgniter
High
CVE-2022-0602
was published
for
tastyigniter/tastyigniter
(Composer)
Apr 6, 2022
Remote Code Execution in Laravel
Critical
CVE-2021-43503
was published
for
laravel/laravel
(Composer)
Apr 9, 2022
•
withdrawn
SQL Injection in Pimcore
High
CVE-2022-1219
was published
for
pimcore/pimcore
(Composer)
Apr 9, 2022
Weak password hash in LiveHelperChat
High
CVE-2022-1235
was published
for
remdex/livehelperchat
(Composer)
Apr 6, 2022
Deleted Admin Can Sign In to Admin Interface
High
CVE-2021-41126
was published
for
october/october
(Composer)
Oct 6, 2021
Improper Neutralization of Formula Elements in a CSV File in Kimai 2
High
CVE-2021-43515
was published
for
kevinpapst/kimai2
(Composer)
Apr 9, 2022
SQL Injection in Pimcore
High
CVE-2022-1339
was published
for
pimcore/pimcore
(Composer)
Apr 14, 2022
HTML Injection in Froxlor
Moderate
CVE-2020-29653
was published
for
froxlor/froxlor
(Composer)
Apr 14, 2022
Persistent Cross-site Scripting vulnerability in PrivateBin
High
CVE-2022-24833
was published
for
privatebin/privatebin
(Composer)
Apr 12, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-1351
was published
for
pimcore/pimcore
(Composer)
Apr 15, 2022
Improper Access Control in Shopware
High
CVE-2022-24872
was published
for
shopware/core
(Composer)
Apr 22, 2022
Cross-site Scripting in snipe-it
Moderate
CVE-2022-1380
was published
for
snipe/snipe-it
(Composer)
Apr 17, 2022
SQL Injection found in Pimcore
High
CVE-2022-1429
was published
for
pimcore/pimcore
(Composer)
Apr 23, 2022
Improper Privilege Management in Concrete CMS
High
CVE-2021-22966
was published
for
concrete5/core
(Composer)
Nov 23, 2021
Cross-site Scripting in Microweber
Moderate
CVE-2022-1439
was published
for
microweber/microweber
(Composer)
Apr 23, 2022
Arbitrary file upload in ShopXO
High
CVE-2021-41938
was published
for
shopxo/shopxo
(Composer)
May 20, 2022
ProTip!
Advisories are also available from the
GraphQL API