Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,861 advisories

Loading
Cross-site Scripting in microweber Moderate
CVE-2022-0678 was published for microweber/microweber (Composer) Feb 20, 2022
Path traversal in pimcore Moderate
CVE-2022-0665 was published for pimcore/pimcore (Composer) Feb 23, 2022
Open Redirect in AllTube Moderate
CVE-2022-0692 was published for rudloff/alltube (Composer) Feb 23, 2022
hitisec
Credited to hitisec
Improper Authorization in dolibarr/dolibarr Moderate
CVE-2022-0731 was published for dolibarr/dolibarr (Composer) Feb 24, 2022
Missing server signature validation in OctoberCMS Moderate
CVE-2022-23655 was published for october/system (Composer) Feb 24, 2022
EC-CUBE improperly handles HTTP Host header values Moderate
CVE-2022-25355 was published for ec-cube/ec-cube (Composer) Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis Moderate
CVE-2021-44565 was published for francoisjacquet/rosariosis (Composer) Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis Moderate
CVE-2021-44566 was published for francoisjacquet/rosariosis (Composer) Feb 25, 2022
Logic error in dolibarr/dolibarr Moderate
CVE-2022-0746 was published for dolibarr/dolibarr (Composer) Feb 26, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0763 was published for microweber/microweber (Composer) Feb 27, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0723 was published for microweber/microweber (Composer) Feb 27, 2022
Exposure of Resource to Wrong Sphere in microweber Moderate
CVE-2022-0762 was published for microweber/microweber (Composer) Feb 27, 2022
Cross site scripting in LibreNMS Moderate
CVE-2022-0772 was published for librenms/librenms (Composer) Feb 28, 2022
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4 Moderate
CVE-2022-24712 was published for codeigniter4/framework (Composer) Mar 1, 2022
Improper regex in htaccess file Moderate
CVE-2022-25769 was published for mautic/core (Composer) Mar 1, 2022
mollux
Credited to mollux
Cross-site Scripting in Cipi Moderate
CVE-2022-26332 was published for andreapollastri/cipi (Composer) Mar 2, 2022
Cross site scripting in getgrav/grav Moderate
CVE-2022-0743 was published for getgrav/grav (Composer) Mar 2, 2022
Cross-site Scripting in GeniXCMS Moderate
CVE-2022-24563 was published for genix/cms (Composer) Mar 4, 2022
Cross-site Scripting in Subrion CMS Moderate
CVE-2020-18324 was published for intelliants/subrion (Composer) Mar 5, 2022
Cross-site Scripting in intelliants/subrion Moderate
CVE-2020-18325 was published for intelliants/subrion (Composer) Mar 5, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-0832 was published for pimcore/pimcore (Composer) Mar 5, 2022
Cross-site Scripting in Pimcore Moderate
CVE-2022-0831 was published for pimcore/pimcore (Composer) Mar 5, 2022
Cross-site Scripting in BookStack Moderate
CVE-2022-0877 was published for ssddanbrown/bookstack (Composer) Mar 9, 2022
Shopware guest session is shared between customers Moderate
CVE-2022-24745 was published for shopware/platform (Composer) Mar 10, 2022
HTML injection possibility in voucher code form in Shopware Moderate
CVE-2022-24746 was published for shopware/core (Composer) Mar 10, 2022
ProTip! Advisories are also available from the GraphQL API