GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,726
Maven
5,000+
npm
4,331
NuGet
763
pip
4,107
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,887 advisories
Filter by severity
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
Moderate
CVE-2025-3640
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Moderate
CVE-2025-3636
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle reveals student identities through assignment submissions search on anonymous submissions
Moderate
CVE-2025-3628
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle makes some user data available before completing second factor with MFA enabled
Moderate
CVE-2025-3627
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle shows hidden grades to users without permission on some grade reports
Moderate
CVE-2025-32045
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle self enrollment available before completing second factor with MFA enabled
Moderate
CVE-2025-3634
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle reflected XSS via H5P error message
Moderate
CVE-2024-43439
was published
for
moodle/moodle
(Composer)
Nov 11, 2024
Yii2 Gii Cross-site Scripting vulnerability
Moderate
CVE-2022-34297
was published
for
yiisoft/yii2-gii
(Composer)
Dec 10, 2022
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
Moderate
CVE-2022-47407
was published
for
fixpunkt/fp-masterquiz
(Composer)
Dec 14, 2022
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
OctoberCMS Cross-Site Scripting
Moderate
CVE-2017-15284
was published
for
october/rain
(Composer)
May 13, 2022
Laravel Starter Cross Site Scripting (XSS)
Moderate
CVE-2025-26159
was published
for
nasirkhan/laravel-starter
(Composer)
Apr 22, 2025
MantisBT vulnerable to CSRF and Open Redirect attacks
Moderate
CVE-2017-7620
was published
for
mantisbt/mantisbt
(Composer)
May 17, 2022
MODX Revolution XSS via HTTP Host header
Moderate
CVE-2017-9071
was published
for
modx/revolution
(Composer)
May 17, 2022
MODX Revolution cross-site scripting vulnerability
Moderate
CVE-2017-9070
was published
for
modx/revolution
(Composer)
May 17, 2022
MODX Revolution Reflected XSS
Moderate
CVE-2017-9068
was published
for
modx/revolution
(Composer)
May 17, 2022
TeamPass vulnerable to Cross-site Scripting
Moderate
CVE-2015-7562
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
SilverStripe Subsite weakens file permissions
Moderate
CVE-2022-42949
was published
for
silverstripe/subsites
(Composer)
Dec 19, 2022
PEAR HTTP_Request2 vulnerable to Cross-site Scripting
Moderate
CVE-2025-43717
was published
for
pear/http_request2
(Composer)
Apr 17, 2025
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
Cross site scripting via input unit widget
Moderate
CVE-2023-36806
was published
for
contao/core-bundle
(Composer)
Jul 25, 2023
Cross-site Scripting in MobileDetect
Moderate
CVE-2018-25080
was published
for
mobiledetect/mobiledetectlib
(Composer)
Feb 4, 2023
ProTip!
Advisories are also available from the
GraphQL API