GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,870 advisories
Filter by severity
Magento Open Source affected by Improper Input Validation
Low
CVE-2023-29293
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29292
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Server-Side Request Forgery (SSRF)
Moderate
CVE-2023-29291
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-29290
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows XML Injection
Moderate
CVE-2023-29289
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Information Exposure
Moderate
CVE-2023-29287
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-29288
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows Improper Access Control
Moderate
CVE-2022-35689
was published
for
magento/community-edition
(Composer)
Oct 15, 2022
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows Improper Access Control
Moderate
CVE-2023-22250
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows Incorrect Authorization
Moderate
CVE-2023-22251
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)
High
CVE-2022-35698
was published
for
magento/community-edition
(Composer)
Oct 15, 2022
Magento Open Source allows Cross-Site Request Forgery (CSRF)
Moderate
CVE-2021-39864
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento LTS vulnerable to stored XSS in theme config fields
Low
CVE-2025-27400
was published
for
openmage/magento-lts
(Composer)
Mar 3, 2025
Improper Authorization vulnerability in Magento and Adobe Commerce
Critical
CVE-2025-24434
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Mautic vulnerable to Improper Access Control in UI upgrade process
High
CVE-2022-25768
was published
for
mautic/core
(Composer)
Sep 18, 2024
Silverstripe Flash Clipboard Reflected XSS
Moderate
CVE-2019-12205
was published
for
silverstripe/admin
(Composer)
May 24, 2022
Magento stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2025-24438
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24435
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Low
CVE-2025-24432
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability
Low
CVE-2025-24430
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Low
CVE-2025-24429
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24427
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2025-24428
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Improper Access Control vulnerability
Moderate
CVE-2025-24424
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API