Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,870 advisories

Loading
Server Side Twig Template Injection Critical
CVE-2022-21686 was published for prestashop/prestashop (Composer) Jan 27, 2022
Brum3ns
Cross-site Scripting in Crater Invoice Moderate
CVE-2022-0372 was published for bytefury/crater (Composer) Jan 28, 2022
Cross Site Request Forgery in Moodle High
CVE-2022-0335 was published for moodle/moodle (Composer) Jan 28, 2022
Insufficient user authorization in Moodle Moderate
CVE-2022-0334 was published for moodle/moodle (Composer) Jan 28, 2022
Insufficient user authorization in Moodle Low
CVE-2022-0333 was published for moodle/moodle (Composer) Jan 28, 2022
SQL injection in Moodle Critical
CVE-2022-0332 was published for moodle/moodle (Composer) Jan 28, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0378 was published for microweber/microweber (Composer) Jan 28, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0379 was published for microweber/microweber (Composer) Jan 28, 2022
Cross-site Scripting in phpmyadmin Moderate
CVE-2022-23808 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
Improper Authentication in phpmyadmin Moderate
CVE-2022-23807 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
Cross-site Scripting in pimcore Moderate
CVE-2022-0348 was published for pimcore/pimcore (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0375 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0374 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0370 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0387 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting when rendering error messages in laminas-form Moderate
CVE-2022-23598 was published for laminas/laminas-form (Composer) Jan 28, 2022
Xerkus
Cross-site Scripting in LiveHelperChat Moderate
CVE-2022-0395 was published for remdex/livehelperchat (Composer) Jan 29, 2022
Path Traversal in the Logs plugin for Craft CMS Moderate
CVE-2022-23409 was published for ether/logs (Composer) Feb 1, 2022
Cross-site Scripting in showdoc Moderate
CVE-2021-4172 was published for showdoc/showdoc (Composer) Feb 1, 2022
CSRF token missing in Symfony High
CVE-2022-23601 was published for symfony/framework-bundle (Composer) Feb 1, 2022
jderusse nexxome
ovrflo
Cross-site Scripting in LiveHelperChat Moderate
CVE-2022-0394 was published for remdex/livehelperchat (Composer) Feb 1, 2022
Dolibarr vulnerable to Improper Validation of Specified Quantity in Input Moderate
CVE-2022-0414 was published for dolibarr/dolibarr (Composer) Feb 1, 2022
RosarioSIS XSS Vulnerability Moderate
CVE-2021-45416 was published for francoisjacquet/rosariosis (Composer) Feb 2, 2022
Cross-site Scripting in Beanstalk console Moderate
CVE-2022-0501 was published for ptrofimov/beanstalk_console (Composer) Feb 6, 2022
Business Logic Errors in SilverStripe Framework Moderate
CVE-2022-0227 was published for silverstripe/framework (Composer) Feb 6, 2022
ProTip! Advisories are also available from the GraphQL API