GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
personnummer/php vulnerable to Improper Input Validation
Low
GHSA-2p6g-gjp8-ggg9
was published
for
personnummer/personnummer
(Composer)
Sep 9, 2020
mezzio-swoole Applications Using Diactoros Vulnerable to HTTP Host Header Attack
High
GHSA-c8rp-cgf4-937w
was published
for
mezzio/mezzio-swoole
(Composer)
Jul 29, 2022
Islandora 2.0 before 2.4.1 could allow any user to upload content into a repository
Critical
GHSA-m58q-qq5h-mgqq
was published
for
islandora/islandora
(Composer)
Jul 21, 2022
OroCommerce vulnerable to XSS when adding class name to Selector Manager on pages that use GrapeJS editor
Moderate
GHSA-6f85-3f8q-qc94
was published
for
oro/commerce
(Composer)
Jul 15, 2022
Potential XSS injection In PrestaShop contactform
High
CVE-2020-15178
was published
for
prestashop/contactform
(Composer)
Sep 15, 2020
Bypass of CMS Safe Mode Security Feature
Moderate
GHSA-q37h-jhf3-85cj
was published
for
wintercms/winter
(Composer)
Jul 15, 2022
XML-RPC for PHP allows access to local files via malicious argument to the Client::send method
Moderate
GHSA-m95x-m25c-w9mp
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP's `Wrapper::buildClientWrapperCode` method allows code injection via malicious `$client` argument
Moderate
GHSA-7vcx-v65q-9wpg
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
XML-RPC for PHP's debugger vulnerable to possible XSS attack
Moderate
GHSA-pxqj-xrv5-qvjf
was published
for
phpxmlrpc/phpxmlrpc
(Composer)
Jan 11, 2023
Improperly checked IDs on itemstacks received from the client leading to server crash in PocketMine-MP
High
GHSA-fqx3-r75h-vc89
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 7, 2022
Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5
Moderate
CVE-2020-26255
was published
for
getkirby/cms
(Composer)
Dec 8, 2020
Login timing attack in ezsystems/ezplatform-kernel
Critical
GHSA-342c-vcff-2ff2
was published
for
ezsystems/ezplatform-kernel
(Composer)
Jun 2, 2022
XSS in various backend modules due to (un)escaping in JS notification module
Moderate
GHSA-jfxf-4frr-9j3q
was published
for
neos/neos
(Composer)
May 25, 2022
Login timing attack in ibexa/core
Critical
GHSA-2x4v-g8cx-jxrq
was published
for
ibexa/core
(Composer)
Jun 2, 2022
Insufficient type validation in pocketmine/pocketmine-mp
High
GHSA-g5rr-p69h-7v3g
was published
for
pocketmine/pocketmine-mp
(Composer)
Apr 22, 2022
Denial-of-service vulnerability processing large chat messages containing many newlines
Moderate
GHSA-gj94-v4p9-w672
was published
for
pocketmine/pocketmine-mp
(Composer)
May 25, 2022
Buffer length underflow in LoginPacket causing unchecked exceptions to be thrown
High
GHSA-5jfw-35xp-5m42
was published
for
pocketmine/bedrock-protocol
(Composer)
Apr 5, 2022
Automatic named constructor discovery in Valinor
High
GHSA-xhr8-mpwq-2rr2
was published
for
cuyz/valinor
(Composer)
Apr 1, 2022
Improper Certificate Validation in node-sass affects eZ Platform
Moderate
GHSA-6v6p-g8cg-2hgg
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
Apr 1, 2022
XSS Injection Vulnerability
Low
GHSA-wf98-vxv9-jqfv
was published
for
craftcms/cms
(Composer)
Apr 5, 2022
Arbitrary shell execution
High
GHSA-mhfv-8rc9-w38c
was published
for
squizlabs/php_codesniffer
(Composer)
Mar 26, 2022
Object injection in cookie driver in phpfastcache
Moderate
CVE-2019-16774
was published
for
phpfastcache/phpfastcache
(Composer)
Dec 12, 2019
Possibility for Denial of Service by overwriting PHP files with language exports
Moderate
GHSA-3fvf-2gp4-89wq
was published
for
barryvdh/laravel-translation-manager
(Composer)
Mar 18, 2022
Arbitrary shell execution
High
GHSA-3988-h75v-hwf6
was published
for
squizlabs/php_codesniffer
(Composer)
Mar 26, 2022
Improperly checked metadata on tools/armour itemstacks received from the client
High
GHSA-46c5-pfj8-fv65
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 18, 2022
ProTip!
Advisories are also available from the
GraphQL API