GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,665
Maven
5,000+
npm
4,294
NuGet
760
pip
4,073
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,861 advisories
Filter by severity
Cross-site Scripting in microweber
Moderate
CVE-2022-0678
was published
for
microweber/microweber
(Composer)
Feb 20, 2022
Path traversal in pimcore
Moderate
CVE-2022-0665
was published
for
pimcore/pimcore
(Composer)
Feb 23, 2022
Open Redirect in AllTube
Moderate
CVE-2022-0692
was published
for
rudloff/alltube
(Composer)
Feb 23, 2022
Improper Authorization in dolibarr/dolibarr
Moderate
CVE-2022-0731
was published
for
dolibarr/dolibarr
(Composer)
Feb 24, 2022
Missing server signature validation in OctoberCMS
Moderate
CVE-2022-23655
was published
for
october/system
(Composer)
Feb 24, 2022
EC-CUBE improperly handles HTTP Host header values
Moderate
CVE-2022-25355
was published
for
ec-cube/ec-cube
(Composer)
Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44565
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44566
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
Logic error in dolibarr/dolibarr
Moderate
CVE-2022-0746
was published
for
dolibarr/dolibarr
(Composer)
Feb 26, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0763
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0723
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Exposure of Resource to Wrong Sphere in microweber
Moderate
CVE-2022-0762
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross site scripting in LibreNMS
Moderate
CVE-2022-0772
was published
for
librenms/librenms
(Composer)
Feb 28, 2022
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4
Moderate
CVE-2022-24712
was published
for
codeigniter4/framework
(Composer)
Mar 1, 2022
Improper regex in htaccess file
Moderate
CVE-2022-25769
was published
for
mautic/core
(Composer)
Mar 1, 2022
Cross-site Scripting in Cipi
Moderate
CVE-2022-26332
was published
for
andreapollastri/cipi
(Composer)
Mar 2, 2022
Cross site scripting in getgrav/grav
Moderate
CVE-2022-0743
was published
for
getgrav/grav
(Composer)
Mar 2, 2022
Cross-site Scripting in GeniXCMS
Moderate
CVE-2022-24563
was published
for
genix/cms
(Composer)
Mar 4, 2022
Cross-site Scripting in Subrion CMS
Moderate
CVE-2020-18324
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in intelliants/subrion
Moderate
CVE-2020-18325
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0832
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0831
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
Cross-site Scripting in BookStack
Moderate
CVE-2022-0877
was published
for
ssddanbrown/bookstack
(Composer)
Mar 9, 2022
Shopware guest session is shared between customers
Moderate
CVE-2022-24745
was published
for
shopware/platform
(Composer)
Mar 10, 2022
HTML injection possibility in voucher code form in Shopware
Moderate
CVE-2022-24746
was published
for
shopware/core
(Composer)
Mar 10, 2022
ProTip!
Advisories are also available from the
GraphQL API