GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,868
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,117
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,869 advisories
Filter by severity
Creation of order credits was not validated by acl in admin orders
Low
GHSA-g7w8-pp9w-7p32
was published
for
shopware/core
(Composer)
Jun 28, 2021
Private files publicly accessible with Cloud Storage providers
High
GHSA-vrf2-xghr-j52v
was published
for
shopware/core
(Composer)
Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api
Moderate
GHSA-gpmh-g94g-qrhr
was published
for
shopware/core
(Composer)
Jun 28, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API
Moderate
CVE-2021-32720
was published
for
sylius/sylius
(Composer)
Jun 29, 2021
Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem
Critical
CVE-2021-32708
was published
for
league/flysystem
(Composer)
Jun 29, 2021
Missing Authentication for Critical Function
Moderate
CVE-2021-32709
was published
for
shopware/platform
(Composer)
Jun 29, 2021
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
XSS Injection in Media Collection Title was possible
Moderate
CVE-2021-32737
was published
for
sulu/sulu
(Composer)
Jul 2, 2021
Craft CMS Cross-site Scripting Vulnerability
Moderate
CVE-2021-27902
was published
for
craftcms/cms
(Composer)
Jul 2, 2021
Craft CMS Remote Code Injection
Critical
CVE-2021-27903
was published
for
craftcms/cms
(Composer)
Jul 2, 2021
Cross-site scripting (XSS) from field and configuration text displayed in the Panel
High
CVE-2021-32735
was published
for
getkirby/cms
(Composer)
Jul 2, 2021
Files or Directories Accessible to External Parties in ether/logs
High
CVE-2021-32752
was published
for
ether/logs
(Composer)
Jul 12, 2021
SQL injection in pimcore/pimcore
High
CVE-2021-23405
was published
for
pimcore/pimcore
(Composer)
Jul 13, 2021
Cross-site Scripting in Froala WYSIWYG Editor
Moderate
CVE-2021-28114
was published
for
froala/wysiwyg-editor
(Composer)
Jul 19, 2021
Cross-Site Scripting in Page Preview
Moderate
CVE-2021-32667
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Query Generator & Query View
Moderate
CVE-2021-32668
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Backend Grid View
Moderate
CVE-2021-32669
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Information Disclosure in User Authentication
Moderate
CVE-2021-32767
was published
for
typo3/cms
(Composer)
Jul 26, 2021
Incorrect Authorization in TeamPass
High
CVE-2020-12477
was published
for
nilsteampassnet/teampass
(Composer)
Jul 26, 2021
Missing Authorization in TeamPass
High
CVE-2020-11671
was published
for
nilsteampassnet/teampass
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12698
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12700
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Incorrect Authorization in TYPO3 extension
Moderate
CVE-2020-25025
was published
for
localizationteam/l10nmgr
(Composer)
Jul 26, 2021
Improper Input Validation in Centreon Web
High
CVE-2019-16405
was published
for
centreon/centreon
(Composer)
Jul 28, 2021
ProTip!
Advisories are also available from the
GraphQL API