GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
Stored cross-site scripting in Snipe-IT
Moderate
CVE-2022-1445
was published
for
snipe/snipe-it
(Composer)
Apr 25, 2022
SQL injection in helloxz/imgurl
High
CVE-2022-29305
was published
for
helloxz/imgurl
(Composer)
May 25, 2022
Cross-site Scripting in Jirafeau
Moderate
CVE-2022-30110
was published
for
mojo42/jirafeau
(Composer)
May 18, 2022
CSRF token exposure in TYPO3 extension
Moderate
CVE-2021-36793
was published
for
lms/routes
(Composer)
Sep 2, 2021
Kirby .dev domains and some reverse proxy setups were treated as local
Moderate
CVE-2020-26253
was published
for
getkirby/cms
(Composer)
Jan 14, 2021
Server-Side Request Forgery (SSRF) in Shopware
High
CVE-2022-24871
was published
for
shopware/core
(Composer)
Apr 22, 2022
PHPMailer susceptible to arbitrary code execution
High
CVE-2008-5619
was published
for
phpmailer/phpmailer
(Composer)
May 14, 2022
snipe-it vulnerable to cross-site scripting (XSS)
Moderate
CVE-2022-3035
was published
for
snipe/snipe-it
(Composer)
Aug 30, 2022
exceedone/exment and exceedone/laravel-admin SQL Injection vulnerability
High
CVE-2022-37333
was published
for
exceedone/exment
(Composer)
Aug 25, 2022
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2022-3072
was published
for
francoisjacquet/rosariosis
(Composer)
Sep 2, 2022
Subrion CMS 4.2.1 vulnerable to cross-site scripting in admin panel
Moderate
CVE-2022-37059
was published
for
intelliants/subrion
(Composer)
Aug 29, 2022
Command injection in czproject/git-php
High
CVE-2022-25866
was published
for
czproject/git-php
(Composer)
Apr 26, 2022
Cross site scripting in facturascripts
Critical
CVE-2022-1457
was published
for
neorazorx/facturascripts
(Composer)
Apr 26, 2022
Rank Math SEO plugin vulnerable to Server-Side Request Forgery
Critical
CVE-2022-36376
was published
for
rankmath/seo-by-rank-math
(Composer)
Sep 10, 2022
Kirby CMS 2.5.12 Cross-site Request Forgery
Moderate
CVE-2018-14519
was published
for
getkirby/cms
(Composer)
Aug 25, 2022
Froxlor vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2022-3017
was published
for
froxlor/froxlor
(Composer)
Aug 29, 2022
baserproject/basercms vulnerable to cross-site scripting (XSS) vulnerability
Moderate
CVE-2022-39325
was published
for
baserproject/basercms
(Composer)
Nov 28, 2022
TYPO3 CMS vulnerable to User Enumeration via Response Timing
Moderate
CVE-2022-36105
was published
for
typo3/cms
(Composer)
Sep 16, 2022
TYPO3 CMS vulnerable to Denial of Service in Page Error Handling
Moderate
CVE-2022-36104
was published
for
typo3/cms
(Composer)
Sep 16, 2022
Shopware access control list bypassed via crafted specific URLs
Moderate
CVE-2022-36102
was published
for
shopware/shopware
(Composer)
Sep 16, 2022
exceedone/exment and exceedone/laravel-admin Cross-site Scripting vulnerability
Moderate
CVE-2022-38080
was published
for
exceedone/exment
(Composer)
Aug 25, 2022
Kirby CMS 2.5.12 Cross-site Scripting
Moderate
CVE-2018-14520
was published
for
getkirby/cms
(Composer)
Aug 25, 2022
Pagekit CMS cross-site scripting in Markdown text box where articles are edited
Moderate
CVE-2022-36573
was published
for
pagekit/pagekit
(Composer)
Aug 29, 2022
PHP Code Injection by malicious block or filename in Smarty
High
CVE-2022-29221
was published
for
smarty/smarty
(Composer)
May 25, 2022
ThinkPHP deserialization vulnerability
Critical
CVE-2022-38352
was published
for
topthink/framework
(Composer)
Sep 16, 2022
ProTip!
Advisories are also available from the
GraphQL API