GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Cross-site Scripting in DayByDay CRM
Moderate
CVE-2022-22109
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
Missing Authorization in DayByDay CRM
Moderate
CVE-2022-22107
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
livehelperchat is vulnerable to Cross-site Scripting
Moderate
CVE-2022-0253
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Moderate
CVE-2022-0245
was published
for
livehelperchat/livehelperchat
(Composer)
Jan 21, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0226
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0231
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
pimcore is vulnerable to Cross-site Scripting
Moderate
CVE-2022-0256
was published
for
pimcore/pimcore
(Composer)
Jan 21, 2022
icecoder is vulnerable to Cross-site Scripting
Moderate
CVE-2021-3862
was published
for
icecoder/icecoder
(Composer)
Jan 21, 2022
Authorization Bypass Through User-Controlled Key in LiveHelperChat
Moderate
CVE-2022-0266
was published
for
remdex/livehelperchat
(Composer)
Jan 21, 2022
pimcore is vulnerable to Cross-site Scripting
Moderate
CVE-2022-0257
was published
for
pimcore/pimcore
(Composer)
Jan 21, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0260
was published
for
pimcore/pimcore
(Composer)
Jan 26, 2022
Business Logic Errors in pimcore
Moderate
CVE-2021-4146
was published
for
pimcore/pimcore
(Composer)
Jan 26, 2022
Cross-site Scripting in showdoc
Moderate
CVE-2021-4172
was published
for
showdoc/showdoc
(Composer)
Feb 1, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0262
was published
for
pimcore/pimcore
(Composer)
Jan 21, 2022
Cross-site Scripting in livehelperchat
Moderate
CVE-2022-0375
was published
for
remdex/livehelperchat
(Composer)
Jan 28, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0251
was published
for
pimcore/pimcore
(Composer)
Jan 27, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0278
was published
for
microweber/microweber
(Composer)
Jan 21, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0378
was published
for
microweber/microweber
(Composer)
Jan 28, 2022
Missing Authorization in Crater Invoice
Moderate
CVE-2022-0203
was published
for
bytefury/crater
(Composer)
Jan 27, 2022
SQL Injection in showdoc
Moderate
CVE-2022-0362
was published
for
showdoc/showdoc
(Composer)
Jan 27, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0285
was published
for
pimcore/pimcore
(Composer)
Jan 21, 2022
Path Traversal in the Logs plugin for Craft CMS
Moderate
CVE-2022-23409
was published
for
ether/logs
(Composer)
Feb 1, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0379
was published
for
microweber/microweber
(Composer)
Jan 28, 2022
Cross-site Scripting in grav
Moderate
CVE-2022-0268
was published
for
getgrav/grav
(Composer)
Jan 27, 2022
Insufficient user authorization in Moodle
Moderate
CVE-2022-0334
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
ProTip!
Advisories are also available from the
GraphQL API