GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,701
Maven
5,000+
npm
4,328
NuGet
761
pip
4,103
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
alextselegidis/easyappointments vulnerable to Stored Cross-site Scripting
Moderate
CVE-2023-2103
was published
for
alextselegidis/easyappointments
(Composer)
Apr 15, 2023
Concrete CMS vulnerable to Reflected Cross-site Scripting
Moderate
CVE-2022-43692
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
phpMyFAQ vulnerable to improper input validation
Moderate
CVE-2023-1754
was published
for
thorsten/phpmyfaq
(Composer)
Mar 31, 2023
Cross-site scripting vulnerabilities in old version of bundled TinyMCE
Moderate
GHSA-wqm8-jx8r-8rcq
was published
for
silverstripe/admin
(Composer)
Apr 26, 2023
Concrete CMS vulnerable to Improper Authentication
Moderate
CVE-2022-43690
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
Pimcore Cross-site Scripting (XSS) in Predefined Properties delete
Moderate
CVE-2023-2615
was published
for
pimcore/pimcore
(Composer)
May 10, 2023
Pimcore Cross-site Scripting (XSS) in name field of Custom Reports
Moderate
CVE-2023-2614
was published
for
pimcore/pimcore
(Composer)
May 10, 2023
Pimcore Cross-site Scripting (XSS) in Static Routes name field
Moderate
CVE-2023-2616
was published
for
pimcore/pimcore
(Composer)
May 11, 2023
Ibexa User Settings are accessible on the front-end for anonymous user
Moderate
GHSA-r3fg-3r88-6x3f
was published
for
ibexa/user
(Composer)
May 10, 2023
PocketMine MP vulnerable to uncontrolled resource consumption via mismatched type of 'InventoryTransactionPacket'
Moderate
GHSA-42qm-8v8m-m78c
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 1, 2023
Silverstripe Form Capture vulnerable to stored cross-site-scripting
Moderate
CVE-2023-28851
was published
for
andrewhaine/silverstripe-form-capture
(Composer)
Apr 3, 2023
Incorrect Authentication in shopware
Moderate
CVE-2022-24748
was published
for
shopware/core
(Composer)
Mar 10, 2022
Microweber before v1.2.20 vulnerable to cross-site scripting
Moderate
CVE-2022-2353
was published
for
microweber/microweber
(Composer)
Jul 10, 2022
Cross-Site Request Forgery in feehi/feehicms
Moderate
CVE-2022-4014
was published
for
feehi/feehicms
(Composer)
Nov 16, 2022
Incorrect Default Permissions and Improper Access Control in snipe-it
Moderate
CVE-2022-0179
was published
for
snipe/snipe-it
(Composer)
Jan 21, 2022
Dolibarr vulnerable to Improper Validation of Specified Quantity in Input
Moderate
CVE-2022-0414
was published
for
dolibarr/dolibarr
(Composer)
Feb 1, 2022
Microweber vulnerable to Improper Validation of Specified Quantity in Input
Moderate
CVE-2022-0596
was published
for
microweber/microweber
(Composer)
Feb 16, 2022
Improper Access Control in snipe/snipe-it
Moderate
CVE-2022-1511
was published
for
snipe/snipe-it
(Composer)
Apr 29, 2022
HTTP caching is marking private HTTP headers as public in Shopware
Moderate
CVE-2022-24747
was published
for
shopware/core
(Composer)
Mar 10, 2022
Sensitive Information Exposure in Sylius
Moderate
CVE-2022-24742
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
Microweber before 1.2.21 allows attacker to bypass IP detection to brute-force password
Moderate
CVE-2022-2368
was published
for
microweber/microweber
(Composer)
Jul 12, 2022
WooCommerce WordPress plugin before 6.6.0 vulnerable to stored HTML injection
Moderate
CVE-2022-2099
was published
for
woocommerce/woocommerce
(Composer)
Jul 18, 2022
Cross-site Scripting (XSS) in baserCMS
Moderate
CVE-2021-20681
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
Firefly III vulnerable to image-based stored XSS
Moderate
CVE-2019-13647
was published
for
grumpydictator/firefly-iii
(Composer)
May 24, 2022
reflected XSS in tribalsystems/zenario
Moderate
CVE-2021-27673
was published
for
tribalsystems/zenario
(Composer)
Jun 8, 2021
ProTip!
Advisories are also available from the
GraphQL API