GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Cross-Site Scripting in Bootstrap Package
Moderate
CVE-2021-21365
was published
for
bk2k/bootstrap-package
(Composer)
Apr 29, 2021
Cross-site scripting in media2click
Moderate
CVE-2021-31778
was published
for
amazing/media2click
(Composer)
Jun 8, 2021
Cross-site scripting in forkcms
Moderate
CVE-2020-23263
was published
for
forkcms/forkcms
(Composer)
Feb 10, 2022
Cross-site Scripting in RosarioSIS
Moderate
CVE-2020-15721
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 10, 2022
Reflected cross-site scripting in francoisjacquet/rosariosis
Moderate
CVE-2020-13278
was published
for
francoisjacquet/rosariosis
(Composer)
May 6, 2021
Cross-site scripting in LavaLite-CMS
Moderate
CVE-2020-23700
was published
for
lavalite/cms
(Composer)
Sep 8, 2021
Cross-site scripting
Moderate
CVE-2021-32713
was published
for
shopware/shopware
(Composer)
Sep 8, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API
Moderate
CVE-2021-32720
was published
for
sylius/sylius
(Composer)
Jun 29, 2021
Server-Side Request Forgery in yoast_seo
Moderate
CVE-2021-31779
was published
for
yoast-seo-for-typo3/yoast_seo
(Composer)
May 21, 2021
Improper Access Control in Dolibarr
Moderate
CVE-2021-25954
was published
for
dolibarr/dolibarr
(Composer)
Aug 11, 2021
Denial of service in direct_mail
Moderate
CVE-2020-12697
was published
for
directmailteam/direct-mail
(Composer)
May 24, 2021
Session Fixation in Subrion CMS
Moderate
CVE-2020-12467
was published
for
intelliants/subrion
(Composer)
Jun 22, 2021
Cross-site scripting in ICEcoder
Moderate
CVE-2021-32106
was published
for
icecoder/icecoder
(Composer)
Sep 9, 2021
Cross-site scripting in PageKit
Moderate
CVE-2021-32245
was published
for
pagekit/pagekit
(Composer)
Jun 22, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12700
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12698
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Use of Cryptographically Weak Pseudo-Random Number Generator in showdoc
Moderate
CVE-2021-3678
was published
for
showdoc/showdoc
(Composer)
Sep 2, 2021
Open redirect in direct_mail
Moderate
CVE-2020-12699
was published
for
directmailteam/direct-mail
(Composer)
May 24, 2021
Cross-site Scripting in the femanager TYPO3 extension
Moderate
CVE-2021-36787
was published
for
in2code/femanager
(Composer)
Sep 1, 2021
Cross-site scripting in feehicms
Moderate
CVE-2020-19709
was published
for
feehi/feehicms
(Composer)
Aug 30, 2021
Cross Site Scripting in Subrion CMS
Moderate
CVE-2020-22392
was published
for
intelliants/subrion
(Composer)
Sep 1, 2021
Cross-site Scripting in the yoast_seo TYPO3 extension
Moderate
CVE-2021-36788
was published
for
yoast-seo-for-typo3/yoast_seo
(Composer)
Sep 1, 2021
Cross-site scripting in Centreon
Moderate
CVE-2021-27676
was published
for
centreon/centreon
(Composer)
Jun 8, 2021
ProTip!
Advisories are also available from the
GraphQL API