GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
515 advisories
Filter by severity
Contao Does Not Invalidate Existing Sessions When Password Changes
Critical
CVE-2019-10641
was published
for
contao/contao
(Composer)
May 14, 2022
phpWhois arbitrary code execution via a crafted whois record
Critical
CVE-2015-5243
was published
for
brightlocal/phpwhois
(Composer)
May 14, 2022
Centreon allows SNMP trap SQL Injection
Critical
CVE-2018-19281
was published
for
centreon/centreon
(Composer)
May 14, 2022
Account takeover in facturascripts
Critical
CVE-2022-1715
was published
for
facturascripts/facturascripts
(Composer)
May 14, 2022
SimpleSAMLphp Use of insecure connection charset (sqlauth module)
Critical
CVE-2018-6521
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 13, 2022
Drupal Entity access bypass for entities that do not have UUIDs or have protected revisions
Critical
CVE-2017-6925
was published
for
drupal/core
(Composer)
May 13, 2022
phpMyAdmin Improper Privilege Management
Critical
CVE-2017-18264
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 13, 2022
Codiad Vulnerable to Shell Command Injection
Critical
CVE-2017-11366
was published
for
codiad/codiad
(Composer)
May 13, 2022
Anchor CMS Logs Credentials
Critical
CVE-2018-7251
was published
for
anchorcms/anchor-cms
(Composer)
May 13, 2022
Moodle Blind SSRF Risk in /badges/mybackpack.php
Critical
CVE-2019-3809
was published
for
moodle/moodle
(Composer)
May 13, 2022
October CMS File Upload Vulnerability
Critical
CVE-2017-1000194
was published
for
october/october
(Composer)
May 13, 2022
Akeneo PIM vulnerable to shell injection in the mass edition
Critical
CVE-2017-1000009
was published
for
akeneo/pim-community-dev
(Composer)
May 13, 2022
elFinder command injection vulnerability in the PHP connector
Critical
CVE-2019-9194
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
Joomla! Object Injection Vulnerability
Critical
CVE-2019-7743
was published
for
joomla/joomla-cms
(Composer)
May 13, 2022
ThinkAdmin Administrator cookies still working after password change
Critical
CVE-2019-11018
was published
for
zoujingli/thinkadmin
(Composer)
May 13, 2022
TeamPass Storing Passwords in a Recoverable Format vulnerability
Critical
CVE-2019-1000001
was published
for
nilsteampassnet/teampass
(Composer)
May 13, 2022
Elefant CMS PHP Code Execution Vulnerability
Critical
CVE-2018-16975
was published
for
elefant/cms
(Composer)
May 13, 2022
Dolibarr SQL Injection vulnerability
Critical
CVE-2018-9019
was published
for
dolibarr/dolibarr
(Composer)
May 13, 2022
Codiad remote code execution vulnerability
Critical
CVE-2018-14009
was published
for
codiad/codiad
(Composer)
May 13, 2022
Contao Does Not Expire Tokens Correctly
Critical
CVE-2019-10643
was published
for
contao/contao
(Composer)
May 13, 2022
Directory Traversal in Studio 42 elFinder
Critical
CVE-2018-9110
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
elFinder Path Traversal vulnerability
Critical
CVE-2018-9109
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
Deserialization of Untrusted Data in topthink/framework
Critical
CVE-2021-23592
was published
for
topthink/framework
(Composer)
May 7, 2022
Incorrect Permission Assignment for Critical Resource in ShopXO
Critical
CVE-2022-28056
was published
for
shopxo/shopxo
(Composer)
May 3, 2022
PEAR::Archive_Tar Directory Traversal vulnerability
Critical
CVE-2006-0931
was published
for
pear/archive_tar
(Composer)
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API