GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,343 advisories
Filter by severity
Unrestricted Upload of File with Dangerous Type in MODX Revolution
High
CVE-2022-26149
was published
for
modx/revolution
(Composer)
Feb 27, 2022
SQL injection in ImpressCMS
High
CVE-2022-26986
was published
for
impresscms/impresscms
(Composer)
Apr 6, 2022
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via FAQ News link parameter
High
CVE-2023-1757
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via adminlog
High
CVE-2023-1878
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) via artlang parameter
High
CVE-2023-1880
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to DOM cross-site scripting (XSS) via configuration privacy note URL parameter
High
CVE-2023-1882
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Microweber vulnerable to stored cross-site scripting (XSS) via X-Forwarded-For header
High
CVE-2023-1881
was published
for
microweber/microweber
(Composer)
Apr 5, 2023
thorsten/phpmyfaq vulnerable to authentication bypass
High
CVE-2023-1886
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Unrestricted Uploads in Concrete5
High
CVE-2020-11476
was published
for
concrete5/concrete5
(Composer)
Nov 3, 2021
Froxlor vulnerable to Command Injection
High
CVE-2023-0315
was published
for
froxlor/froxlor
(Composer)
Jan 16, 2023
thorsten/phpmyfaq vulnerable privilege escalation from improper privilege management
High
CVE-2023-1762
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
Appwrite Server-Side Request Forgery vulnerability
High
CVE-2023-27159
was published
for
appwrite/server-ce
(Composer)
Mar 31, 2023
thorsten/phpmyfaq vulnerable to stored cross-site scripting (XSS) in FAQ comment username parameter
High
CVE-2023-1758
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Cross-site scripting (XSS) from field and configuration text displayed in the Panel
High
CVE-2021-32735
was published
for
getkirby/cms
(Composer)
Jul 2, 2021
Cross site scripting (XSS) in wwbn/avideo
High
GHSA-2fch-hv74-fgw9
was published
for
wwbn/avideo
(Composer)
Apr 26, 2023
CakePHP allows remote attackers to spoof their IP
High
CVE-2016-4793
was published
for
cakephp/cakephp
(Composer)
May 14, 2022
Improper Control of Generation of Code in Twig rendered views
High
CVE-2023-2017
was published
for
shopware/core
(Composer)
Apr 18, 2023
NotrinosERP vulnerable to SQL Injection
High
CVE-2023-24788
was published
for
notrinos/notrinos-erp
(Composer)
Mar 23, 2023
Cachet vulnerable to new line injection during configuration edition
High
CVE-2021-39172
was published
for
cachethq/cachet
(Composer)
Aug 30, 2021
Change in port should be considered a change in origin
High
CVE-2022-31091
was published
for
guzzlehttp/guzzle
(Composer)
Jun 21, 2022
PocketMine-MP vulnerable to improperly checked dropped item count leading to server crash
High
GHSA-h87r-f4vc-mchv
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 6, 2023
Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High
CVE-2022-46464
was published
for
concrete5/concrete5
(Composer)
Dec 6, 2022
•
withdrawn
thorsten/phpmyfaq vulnerable to business logic errors
High
CVE-2023-1887
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
elFinder vulnerable to path traversal in LocalVolumeDriver connector
High
CVE-2023-35840
was published
for
studio-42/elfinder
(Composer)
Jun 14, 2023
phpMyFAQ has insecure HTTP cookies
High
CVE-2022-4409
was published
for
thorsten/phpmyfaq
(Composer)
Dec 11, 2022
ProTip!
Advisories are also available from the
GraphQL API