GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
livehelperchat is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4132
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4131
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2021-4139
was published
for
pimcore/pimcore
(Composer)
Jan 5, 2022
Client-Side JavaScript Prototype Pollution in oro/platform
Moderate
CVE-2021-43852
was published
for
oro/platform
(Composer)
Jan 6, 2022
XSS vulnerability on email template preview page
Moderate
CVE-2021-41236
was published
for
oro/platform
(Composer)
Jan 6, 2022
Cross-Site Request Forgery in Moodle
Moderate
CVE-2020-1692
was published
for
moodle/moodle
(Composer)
Jan 6, 2022
Incorrect Authorization in latte/latte
Critical
CVE-2021-23803
was published
for
latte/latte
(Composer)
Jan 6, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager
Moderate
CVE-2021-23814
was published
for
unisharp/laravel-filemanager
(Composer)
Jan 6, 2022
elgg is vulnerable to Cross-site Scripting
Moderate
CVE-2021-4072
was published
for
elgg/elgg
(Composer)
Jan 6, 2022
invoiceninja is vulnerable to Cross-site Scripting
Moderate
CVE-2021-3977
was published
for
hillelcoren/invoice-ninja
(Composer)
Jan 6, 2022
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-4168
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
Cross-site Scripting in Netgen Tags Bundle
Moderate
CVE-2021-45895
was published
for
netgen/tagsbundle
(Composer)
Jan 6, 2022
Injection in UserFrosting
High
CVE-2021-25994
was published
for
userfrosting/userfrosting
(Composer)
Jan 6, 2022
showdoc is vulnerable to Generation of Error Message Containing Sensitive Information
Moderate
CVE-2022-0079
was published
for
showdoc/showdoc
(Composer)
Jan 6, 2022
Arbitrary PHP code execution in Drupal
Critical
CVE-2019-6339
was published
for
drupal/core
(Composer)
Jan 6, 2022
Deserialization of Untrusted Data in Codeigniter4
High
CVE-2022-21647
was published
for
codeigniter4/framework
(Composer)
Jan 6, 2022
OS Command Injection in Laravel Framework
High
CVE-2020-19316
was published
for
laravel/framework
(Composer)
Jan 6, 2022
Sandbox bypass in Latte templates
High
CVE-2022-21648
was published
for
latte/latte
(Composer)
Jan 6, 2022
Insufficient Session Expiration in shopware
Low
CVE-2022-21652
was published
for
shopware/shopware
(Composer)
Jan 6, 2022
Open redirect in shopware
Moderate
CVE-2022-21651
was published
for
shopware/shopware
(Composer)
Jan 6, 2022
Book page text, count, and author/title length is not limited in PocketMine-MP
Moderate
GHSA-p62j-hrxm-xcxf
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 6, 2022
Uncapped length of skin data fields submitted by players
High
GHSA-c6fg-99pr-25m9
was published
for
pocketmine/pocketmine-mp
(Composer)
Jan 6, 2022
Wechat-php-sdk is affected by a Cross Site Scripting vulnerability.
Moderate
CVE-2021-43678
was published
for
gaoming13/wechat-php-sdk
(Composer)
Jan 7, 2022
Missing Authorization in DayByDay CRM
High
CVE-2022-22111
was published
for
bottelet/flarepoint
(Composer)
Jan 8, 2022
ProTip!
Advisories are also available from the
GraphQL API