GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,290 advisories
Filter by severity
Cross-domain cookie leakage in Guzzle
High
CVE-2022-29248
was published
for
guzzlehttp/guzzle
(Composer)
May 25, 2022
SQL injection in helloxz/imgurl
High
CVE-2022-29305
was published
for
helloxz/imgurl
(Composer)
May 25, 2022
Magento remote code execution vulnerability
High
CVE-2019-8154
was published
for
magento/community-edition
(Composer)
May 24, 2022
Typo3 Vulnerable to Insecure Deserialization
High
CVE-2019-12747
was published
for
typo3/cms
(Composer)
May 24, 2022
TYPO3 Image Processing susceptible to Code Execution
High
CVE-2019-11832
was published
for
typo3/cms
(Composer)
May 24, 2022
Moodle contains CSRF vulnerability
High
CVE-2021-43559
was published
for
moodle/moodle
(Composer)
May 24, 2022
Unrestricted File Upload vulnerability in Firefly III
High
CVE-2021-3846
was published
for
grumpydictator/firefly-iii
(Composer)
May 24, 2022
EC-CUBE Improper access control vulnerability
High
CVE-2021-20778
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
Magento Violation of Secure Design Principles vulnerability in RMA PDF filename formats
High
CVE-2021-28583
was published
for
magento/community-edition
(Composer)
May 24, 2022
Drupal Core Cross-Site Request Forgery (CSRF) vulnerability
High
CVE-2020-13663
was published
for
drupal/core
(Composer)
May 24, 2022
Drupal Core Arbitrary PHP code execution vulnerability
High
CVE-2020-13664
was published
for
drupal/core
(Composer)
May 24, 2022
Grav CMS Arbitrary File Deletion
High
CVE-2020-29555
was published
for
getgrav/grav
(Composer)
May 24, 2022
Grav CMS Cross-Site Request Forgery (CSRF)
High
CVE-2020-29553
was published
for
getgrav/grav
(Composer)
May 24, 2022
ThinkAdmin Admin Panel Access using Default Credentials
High
CVE-2020-35296
was published
for
zoujingli/thinkadmin
(Composer)
May 24, 2022
Magento stored cross-site scripting (XSS) in the customer address upload feature
High
CVE-2021-21030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento OS command injection via the customer attribute save controller
High
CVE-2021-21015
was published
for
magento/community-edition
(Composer)
May 24, 2022
Moodle Arbitrary PHP code execution by site admins via Shibboleth configuration
High
CVE-2021-20187
was published
for
moodle/moodle
(Composer)
May 24, 2022
Codiad Vulnerable to PHP Magic Hash Vulnerability
High
CVE-2020-23355
was published
for
codiad/codiad
(Composer)
May 24, 2022
Zen Cart vulnerable to authenticated remote code execution
High
CVE-2021-3291
was published
for
zencart/zencart
(Composer)
May 24, 2022
CakePHP allows method override parameters to bypass CSRF checks
High
CVE-2020-35239
was published
for
cakephp/cakephp
(Composer)
May 24, 2022
Feehi CMS arbitrary file upload vulnerability
High
CVE-2020-22643
was published
for
feehi/cms
(Composer)
May 24, 2022
MantisBT Incorrect Authorization for bug_revision_view_page.php check
High
CVE-2020-35849
was published
for
mantisbt/mantisbt
(Composer)
May 24, 2022
Dolibarr authenticated Remote Code Execution
High
CVE-2020-35136
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Moodle Denial of Service
High
CVE-2020-25630
was published
for
moodle/moodle
(Composer)
May 24, 2022
Moodle incorrect access control
High
CVE-2020-25629
was published
for
moodle/moodle
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API