GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,114
NuGet
735
pip
3,934
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,867 advisories
Filter by severity
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24437
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Drupal AI Vulnerable to OS Command Injection
Moderate
CVE-2025-31693
was published
for
drupal/ai
(Composer)
Apr 1, 2025
Snipe-IT allows attackers to check whether a user account exists
Moderate
CVE-2022-44381
was published
for
snipe/snipe-it
(Composer)
Dec 25, 2022
Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets
Moderate
CVE-2022-44380
was published
for
snipe/snipe-it
(Composer)
Dec 25, 2022
ThinkPHP Framework vulnerable to remote code execution
Critical
CVE-2022-47945
was published
for
topthink/framework
(Composer)
Dec 23, 2022
Bootstrap Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2024-6531
was published
for
bootstrap
(RubyGems)
Jul 11, 2024
Remote code execution in PHPMailer
Critical
CVE-2016-10033
was published
for
phpmailer/phpmailer
(Composer)
Mar 5, 2020
Remote code execution in PHPMailer
Critical
CVE-2016-10045
was published
for
phpmailer/phpmailer
(Composer)
Mar 5, 2020
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
Typo3 Host Header Spoofing Vulnerability
Moderate
CVE-2014-3941
was published
for
typo3/cms
(Composer)
May 14, 2022
Typo3 Information Disclosure
Moderate
CVE-2014-3946
was published
for
typo3/cms
(Composer)
May 17, 2022
phpMyAdmin Code Injection vulnerability
Critical
CVE-2016-5734
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin vulnerable to Cross-Site Request Forgery
High
CVE-2016-5739
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5733
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5705
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5701
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
TYPO3 Cross-site Scripting vulnerability
Moderate
CVE-2015-8759
was published
for
typo3/cms
(Composer)
May 17, 2022
TYPO3 CMS indexed search Cross-site Scripting vulnerability
Moderate
CVE-2015-8756
was published
for
typo3/cms
(Composer)
May 17, 2022
TYPO3 allows remote attackers to embed Flash videos from external domain
Moderate
CVE-2015-8760
was published
for
typo3/cms
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to spoof content via the url parameter
High
CVE-2015-7873
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
concrete5 vulnerable to Cross-site Scripting
Low
CVE-2015-3989
was published
for
concrete5/concrete5
(Composer)
May 17, 2022
fal_sftp extension for TYPO3 uses weak permissions for sFTP driver files and folders
Moderate
CVE-2014-8327
was published
for
co-stack/fal_sftp
(Composer)
May 17, 2022
yag and pt_extbase extensions for TYPO3 allow remote attackers to bypass access restrictions
High
CVE-2014-6289
was published
for
dl/yag
(Composer)
May 17, 2022
WEC Map (wec_map) extension for TYPO3 allows SQL Injection
High
CVE-2014-6295
was published
for
jbartels/wec-map
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API