GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
530 advisories
Filter by severity
Path manipulation in matyhtf/framework
Critical
CVE-2021-43676
was published
for
matyhtf/framework
(Composer)
Dec 4, 2021
XSS vulnerability leveraged through referrers could allow un-authorized admin access in Mautic
Critical
CVE-2020-35124
was published
for
mautic/core
(Composer)
Jan 19, 2021
Drupal Improper Access Control
Critical
CVE-2019-6342
was published
for
drupal/core
(Composer)
Jan 11, 2024
TCPDF vulnerable to attackers triggering deserialization of arbitrary data
Critical
CVE-2018-17057
was published
for
fooman/tcpdf
(Composer)
Oct 6, 2022
Potential Remote Code Execution in TYPO3 with mediace extension
Critical
CVE-2020-15086
was published
for
friendsoftypo3/mediace
(Composer)
Jul 29, 2020
Missing warning can lead to unauthenticated admin access in SilverStripe
Critical
CVE-2019-12204
was published
for
silverstripe/cms
(Composer)
Nov 12, 2019
Deserialization of Untrusted Data in codeception/codeception
Critical
CVE-2021-23420
was published
for
codeception/codeception
(Composer)
Sep 1, 2021
Magento 2 Community Edition RCE Vulnerability
Critical
CVE-2019-8144
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Insecure Component
Critical
CVE-2019-8136
was published
for
magento/community-edition
(Composer)
May 24, 2022
Server-Side Request Forgery (SSRF) in rudloff/alltube
Critical
CVE-2022-0768
was published
for
rudloff/alltube
(Composer)
Mar 1, 2022
Craft CMS possibility of brute force attempts
Critical
CVE-2019-15929
was published
for
craftcms/cms
(Composer)
May 24, 2022
Symfony Unsafe Cache Serialization Could Enable RCE
Critical
CVE-2019-18889
was published
for
symfony/cache
(Composer)
Dec 2, 2019
Remote CLI Command Execution Vulnerability in CodeIgniter4
Critical
CVE-2022-24711
was published
for
codeigniter4/framework
(Composer)
Mar 1, 2022
Blind SQL injection in shopware
Critical
CVE-2024-22406
was published
for
shopware/core
(Composer)
Jan 17, 2024
ImpressPages CMS RCE
Critical
CVE-2011-4943
was published
for
impresspages/impresspages
(Composer)
Apr 22, 2022
Smarty3 Arbitrary PHP Code Execution
Critical
CVE-2011-1028
was published
for
smarty/smarty
(Composer)
Apr 22, 2022
Typo3 SQL injection due to faulty prepared statements
Critical
CVE-2011-3583
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Typo3 Authentication Bypass
Critical
CVE-2011-4628
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2022-34253
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento Security mitigation bypass vulnerability
Critical
CVE-2020-9579
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento php object injection vulnerability
Critical
CVE-2020-9664
was published
for
magento/core
(Composer)
May 24, 2022
Magento security bypass vulnerability
Critical
CVE-2020-3718
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML injection in the Widgets module
Critical
CVE-2021-21019
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento deserialization vulnerability
Critical
CVE-2020-3716
was published
for
magento/community-edition
(Composer)
May 24, 2022
elFinder Unrestricted File Upload vulnerability
Critical
CVE-2021-43421
was published
for
studio-42/elfinder
(Composer)
Apr 8, 2022
ProTip!
Advisories are also available from the
GraphQL API