GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
Stored Cross-site Scripting in grav
High
CVE-2022-0970
was published
for
getgrav/grav
(Composer)
Mar 16, 2022
DQL injection through sorting parameters blocked
Critical
CVE-2022-24752
was published
for
sylius/grid-bundle
(Composer)
Mar 15, 2022
Improper Restriction of Rendered UI Layers or Frames in Sylius
Moderate
CVE-2022-24733
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
Insufficient Session Expiration in Sylius
High
CVE-2022-24743
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
SQL Injection in WordPress Zero Spam WordPress plugin
Critical
CVE-2022-0254
was published
for
bmarshall511/wordpress_zero_spam
(Composer)
Mar 15, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0946
was published
for
showdoc/showdoc
(Composer)
Mar 15, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0926
was published
for
microweber/microweber
(Composer)
Mar 13, 2022
Cross-site Scripting in microweber
High
CVE-2022-0930
was published
for
microweber/microweber
(Composer)
Mar 13, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0929
was published
for
microweber/microweber
(Composer)
Mar 13, 2022
Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius
Moderate
CVE-2022-24749
was published
for
Sylius/Sylius
(Composer)
Mar 14, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0928
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Unrestricted Upload of File with Dangerous Type in microweber
Moderate
CVE-2022-0912
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Integer Overflow or Wraparound in Microweber
High
CVE-2022-0913
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0962
was published
for
showdoc/showdoc
(Composer)
Mar 15, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0880
was published
for
showdoc/showdoc
(Composer)
Mar 13, 2022
Server-side Template Injection in nystudio107/craft-seomatic
High
CVE-2021-44618
was published
for
nystudio107/craft-seomatic
(Composer)
Mar 12, 2022
Static Code Injection in Microweber
High
CVE-2022-0895
was published
for
microweber/microweber
(Composer)
Mar 11, 2022
Unrestricted Upload of File with Dangerous Type in Microweber
Moderate
CVE-2022-0921
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Unrestricted file upload leads to stored cross-site scripting in Microweber
Moderate
CVE-2022-0906
was published
for
microweber/microweber
(Composer)
Mar 11, 2022
Cross-site Scripting in moodle
Moderate
CVE-2021-43558
was published
for
moodle/moodle
(Composer)
Nov 23, 2021
symfont/process typosquatting malware spoofs symfony/process
High
GHSA-g3j5-mpp2-2fqm
was published
for
symfont/process
(Composer)
Jan 26, 2023
Improper Authorization in grumpydictator/firefly-iii
Moderate
CVE-2023-0298
was published
for
grumpydictator/firefly-iii
(Composer)
Jan 14, 2023
Shopware vulnerable to Improper Control of Generation of Code in Twig rendered views
Critical
CVE-2023-22731
was published
for
shopware/core
(Composer)
Jan 17, 2023
Shopware vulnerable to Improper Input Validation of Clearance sale in cart
Moderate
CVE-2023-22730
was published
for
shopware/core
(Composer)
Jan 17, 2023
Shopware's log module vulnerable to Improper Output Neutralization
Low
CVE-2023-22733
was published
for
shopware/core
(Composer)
Jan 20, 2023
ProTip!
Advisories are also available from the
GraphQL API