Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,781 advisories

Loading
Cross-Site Request Forgery in Moodle Moderate
CVE-2020-1692 was published for moodle/moodle (Composer) Jan 6, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager Moderate
CVE-2021-23814 was published for unisharp/laravel-filemanager (Composer) Jan 6, 2022
streamtw
elgg is vulnerable to Cross-site Scripting Moderate
CVE-2021-4072 was published for elgg/elgg (Composer) Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting Moderate
CVE-2021-3977 was published for hillelcoren/invoice-ninja (Composer) Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4168 was published for showdoc/showdoc (Composer) Jan 6, 2022
Cross-site Scripting in Netgen Tags Bundle Moderate
CVE-2021-45895 was published for netgen/tagsbundle (Composer) Jan 6, 2022
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information Moderate
CVE-2022-0079 was published for showdoc/showdoc (Composer) Jan 6, 2022
Open redirect in shopware Moderate
CVE-2022-21651 was published for shopware/shopware (Composer) Jan 6, 2022
Book page text, count, and author/title length is not limited in PocketMine-MP Moderate
GHSA-p62j-hrxm-xcxf was published for pocketmine/pocketmine-mp (Composer) Jan 6, 2022
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability. Moderate
CVE-2021-43678 was published for gaoming13/wechat-php-sdk (Composer) Jan 7, 2022
Open Redirect in Grav Moderate
CVE-2020-11529 was published for getgrav/grav (Composer) Jan 7, 2022
Missing Authorization in DayByDay CRM Moderate
CVE-2022-22108 was published for bottelet/flarepoint (Composer) Jan 8, 2022
Missing Authorization in DayByDay CRM Moderate
CVE-2022-22107 was published for bottelet/flarepoint (Composer) Jan 8, 2022
Cross-site Scripting in DayByDay CRM Moderate
CVE-2022-22109 was published for bottelet/flarepoint (Composer) Jan 8, 2022
bookstack is vulnerable to Improper Access Control Moderate
CVE-2021-4194 was published for ssddanbrown/bookstack (Composer) Jan 8, 2022
XSS vulnerability in translations Moderate
GHSA-rrgw-3hg3-9x8c was published for oro/platform (Composer) Jan 12, 2022
Logic error in dolibarr Moderate
CVE-2022-0174 was published for dolibarr/dolibarr (Composer) Jan 12, 2022
Microweber Incorrect Permission Assignment for Critical Resource vulnerability Moderate
CVE-2022-0277 was published for microweber/microweber (Composer) Jan 21, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0278 was published for microweber/microweber (Composer) Jan 21, 2022
Cross-site Scripting in pimcore Moderate
CVE-2022-0285 was published for pimcore/pimcore (Composer) Jan 21, 2022
Insufficient Session Expiration in Pterodactyl API Moderate
GHSA-7v3x-h7r2-34jv was published for pterodactyl/panel (Composer) Jan 21, 2022
EgoMaw
Authorization Bypass Through User-Controlled Key in LiveHelperChat Moderate
CVE-2022-0266 was published for remdex/livehelperchat (Composer) Jan 21, 2022
Impersonation of other users (passing XBOX Live authentication) by theft of logins in PocketMine-MP Moderate
GHSA-h79x-98r2-g6qc was published for pocketmine/pocketmine-mp (Composer) Jan 21, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat Moderate
CVE-2022-0245 was published for livehelperchat/livehelperchat (Composer) Jan 21, 2022
Cross-site Scripting in pimcore Moderate
CVE-2022-0262 was published for pimcore/pimcore (Composer) Jan 21, 2022
ProTip! Advisories are also available from the GraphQL API