GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,688
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,883 advisories
Filter by severity
exceedone/exment and exceedone/laravel-admin Cross-site Scripting vulnerability
Moderate
CVE-2022-38080
was published
for
exceedone/exment
(Composer)
Aug 25, 2022
Kirby CMS 2.5.12 Cross-site Scripting
Moderate
CVE-2018-14520
was published
for
getkirby/cms
(Composer)
Aug 25, 2022
Shopware access control list bypassed via crafted specific URLs
Moderate
CVE-2022-36102
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
TYPO3 CMS vulnerable to User Enumeration via Response Timing
Moderate
CVE-2022-36105
was published
for
typo3/cms
(Composer)
Sep 16, 2022
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling
Moderate
CVE-2022-36104
was published
for
typo3/cms
(Composer)
Sep 16, 2022
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Moderate
CVE-2022-39325
was published
for
baserproject/basercms
(Composer)
Nov 28, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2022-3017
was published
for
froxlor/froxlor
(Composer)
Aug 29, 2022
Kirby CMS 2.5.12 Cross-site Request Forgery
Moderate
CVE-2018-14519
was published
for
getkirby/cms
(Composer)
Aug 25, 2022
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2022-3072
was published
for
francoisjacquet/rosariosis
(Composer)
Sep 2, 2022
Subrion CMS 4.2.1 vulnerable to cross-site scripting in admin panel
Moderate
CVE-2022-37059
was published
for
intelliants/subrion
(Composer)
Aug 29, 2022
snipe-it vulnerable to cross-site scripting (XSS)
Moderate
CVE-2022-3035
was published
for
snipe/snipe-it
(Composer)
Aug 30, 2022
Kirby .dev domains and some reverse proxy setups were treated as local
Moderate
CVE-2020-26253
was published
for
getkirby/cms
(Composer)
Jan 14, 2021
Cross-site Scripting in Jirafeau
Moderate
CVE-2022-30110
was published
for
mojo42/jirafeau
(Composer)
May 18, 2022
CSRF token exposure in TYPO3 extension
Moderate
CVE-2021-36793
was published
for
lms/routes
(Composer)
Sep 2, 2021
Stored cross-site scripting in Snipe-IT
Moderate
CVE-2022-1445
was published
for
snipe/snipe-it
(Composer)
Apr 25, 2022
Cross-site Scripting in Microweber
Moderate
CVE-2022-1439
was published
for
microweber/microweber
(Composer)
Apr 23, 2022
Cross-site Scripting in snipe-it
Moderate
CVE-2022-1380
was published
for
snipe/snipe-it
(Composer)
Apr 17, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-1351
was published
for
pimcore/pimcore
(Composer)
Apr 15, 2022
HTML Injection in Froxlor
Moderate
CVE-2020-29653
was published
for
froxlor/froxlor
(Composer)
Apr 14, 2022
Open redirect in wwbn/avideo
Moderate
CVE-2022-27463
was published
for
wwbn/avideo
(Composer)
Apr 6, 2022
Cross-site Scripting in craftcms/cms
Moderate
CVE-2022-28378
was published
for
craftcms/cms
(Composer)
Apr 4, 2022
Incorrect Access Control in ImpressCMS
Moderate
CVE-2021-26598
was published
for
impresscms/impresscms
(Composer)
Mar 29, 2022
Cross-site Scripting in teampass
Moderate
CVE-2022-26980
was published
for
nilsteampassnet/teampass
(Composer)
Mar 29, 2022
Cross-Site Request Forgery in Anchor CMS
Moderate
CVE-2022-25576
was published
for
anchorcms/anchor-cms
(Composer)
Mar 26, 2022
Cross-site Scripting in Fork CMS
Moderate
CVE-2022-0145
was published
for
forkcms/forkcms
(Composer)
Mar 25, 2022
ProTip!
Advisories are also available from the
GraphQL API