GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,688
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,340 advisories
Filter by severity
Magento XML Injection vulnerability in the Widgets Update Layout
High
CVE-2021-36022
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XML Injection vulnerability in the 'City' field
High
CVE-2021-36020
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento DOM-based Cross-Site Scripting (XSS) vulnerability
High
CVE-2024-39400
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Path Traversal vulnerability
High
CVE-2024-39399
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento Stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2024-39403
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento does not properly restrict excessive authentication attempts
High
CVE-2024-39398
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento OS Command ('OS Command Injection') vulnerability
High
CVE-2024-39402
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Magento OS Command ('OS Command Injection') vulnerability
High
CVE-2024-39401
was published
for
magento/community-edition
(Composer)
Aug 14, 2024
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
CVE-2024-11954
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Smarty vulnerable to PHP Code Injection by malicious attribute in extends-tag
High
CVE-2024-35226
was published
for
smarty/smarty
(Composer)
May 29, 2024
smarty Cross-site Scripting vulnerability in Javascript escaping
High
CVE-2023-28447
was published
for
smarty/smarty
(Composer)
Mar 29, 2023
TCPDF has incorrect comparison
High
CVE-2024-56522
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
Statamic Vulnerable to Superadmin Account Takeover via Stored Cross-Site Scripting and Lack of Proper X-CSRF-TOKEN Server-Side Validation
High
CVE-2025-64112
was published
for
statamic/cms
(Composer)
Oct 30, 2025
Drupal Acquia DAM allows Forceful Browsing
High
CVE-2025-9954
was published
for
drupal/acquia_dam
(Composer)
Oct 30, 2025
Drupal Simple OAuth (OAuth2) & OpenID Connect allows Authentication Bypass
High
CVE-2025-12466
was published
for
drupal/simple_oauth
(Composer)
Oct 30, 2025
Drupal CivicTheme Design System allows Forceful Browsing
High
CVE-2025-12082
was published
for
drupal/civictheme
(Composer)
Oct 30, 2025
Moodle vulnerable to brute-force password guesses
High
CVE-2025-62399
was published
for
moodle/moodle
(Composer)
Oct 23, 2025
Admidio Vulnerable to Authenticated SQL Injection in Member Assignment Functionality
High
CVE-2025-62617
was published
for
admidio/admidio
(Composer)
Oct 22, 2025
Magento Improper Authorization leading to security feature bypass
High
CVE-2025-43585
was published
for
magento/community-edition
(Composer)
Jun 10, 2025
Magento Cross-Site Request Forgery (CSRF) vulnerability
High
CVE-2025-49555
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Craft CMS has a potential RCE with a compromised security key
High
CVE-2025-23209
was published
for
craftcms/cms
(Composer)
Jan 21, 2025
Account Takeover in Octobercms
High
CVE-2021-32648
was published
for
october/system
(Composer)
Aug 30, 2021
Directory Traversal in Archive_Tar
High
CVE-2020-36193
was published
for
pear/archive_tar
(Composer)
Apr 22, 2021
Drupal core Unrestricted Upload of File with Dangerous Type
High
CVE-2020-13671
was published
for
drupal/core
(Composer)
Oct 12, 2021
ProTip!
Advisories are also available from the
GraphQL API