GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,325
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Cross-site Scripting in librenms
Moderate
CVE-2022-0576
was published
for
librenms/librenms
(Composer)
Feb 15, 2022
Cross-Site Request Forgery microweber
Moderate
CVE-2022-0638
was published
for
microweber/microweber
(Composer)
Feb 18, 2022
Generation of Error Message Containing Sensitive Information in Snipe-IT
Moderate
CVE-2022-0622
was published
for
snipe/snipe-it
(Composer)
Feb 18, 2022
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
Moderate
CVE-2022-37251
was published
for
craftcms/cms
(Composer)
Sep 17, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0723
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross-site Scripting in Cipi
Moderate
CVE-2022-26332
was published
for
andreapollastri/cipi
(Composer)
Mar 2, 2022
Incorrect authorization in Drupal core
Moderate
CVE-2022-25270
was published
for
drupal/core
(Composer)
Feb 18, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0678
was published
for
microweber/microweber
(Composer)
Feb 20, 2022
Business Logic Errors in microweber
Moderate
CVE-2022-0689
was published
for
microweber/microweber
(Composer)
Feb 20, 2022
Logic error in dolibarr/dolibarr
Moderate
CVE-2022-0746
was published
for
dolibarr/dolibarr
(Composer)
Feb 26, 2022
Missing server signature validation in OctoberCMS
Moderate
CVE-2022-23655
was published
for
october/system
(Composer)
Feb 24, 2022
Path traversal in pimcore
Moderate
CVE-2022-0665
was published
for
pimcore/pimcore
(Composer)
Feb 23, 2022
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4
Moderate
CVE-2022-24712
was published
for
codeigniter4/framework
(Composer)
Mar 1, 2022
Cross site scripting in getgrav/grav
Moderate
CVE-2022-0743
was published
for
getgrav/grav
(Composer)
Mar 2, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44566
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44565
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
Cross-site Scripting in GeniXCMS
Moderate
CVE-2022-24563
was published
for
genix/cms
(Composer)
Mar 4, 2022
Cross-site Scripting in Subrion CMS
Moderate
CVE-2020-18324
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in BookStack
Moderate
CVE-2022-0877
was published
for
ssddanbrown/bookstack
(Composer)
Mar 9, 2022
Shopware guest session is shared between customers
Moderate
CVE-2022-24745
was published
for
shopware/platform
(Composer)
Mar 10, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0763
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross site scripting in LibreNMS
Moderate
CVE-2022-0772
was published
for
librenms/librenms
(Composer)
Feb 28, 2022
Cross-site Scripting in intelliants/subrion
Moderate
CVE-2020-18325
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0832
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0831
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
ProTip!
Advisories are also available from the
GraphQL API