GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Moodle Setting for blocked hosts list can be bypassed with multiple A record hostnames
Moderate
CVE-2018-1043
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Improper Privilege Management
Moderate
CVE-2018-1134
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Cross-site Scripting
Moderate
CVE-2018-1136
was published
for
moodle/moodle
(Composer)
May 13, 2022
Paymorrow Improper Input Validation vulnerability
Moderate
CVE-2018-14020
was published
for
oxid-esales/paymorrow-module
(Composer)
May 13, 2022
Showdoc Unauthenticated Access
Moderate
CVE-2018-19620
was published
for
showdoc/showdoc
(Composer)
May 13, 2022
Kirby XSS Vulnerability
Moderate
CVE-2017-16807
was published
for
getkirby/cms
(Composer)
May 14, 2022
Centreon XSS Vulnerability
Moderate
CVE-2018-19311
was published
for
centreon/centreon
(Composer)
May 14, 2022
Centreon XSS Vulnerability
Moderate
CVE-2018-19280
was published
for
centreon/centreon
(Composer)
May 14, 2022
Centreon Cross-site Scripting Vulnerability
Moderate
CVE-2015-7672
was published
for
centreon/centreon
(Composer)
May 14, 2022
Moodle SSRF Vulnerability
Moderate
CVE-2018-1042
was published
for
moodle/moodle
(Composer)
May 14, 2022
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS)
Moderate
CVE-2018-9861
was published
for
ckeditor-dev
(Composer)
May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2683
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2681
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2682
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Shopware XXE Vulnerability
Moderate
CVE-2017-18357
was published
for
shopware/shopware
(Composer)
May 14, 2022
SimpleSAMLphp allows timing side-channel attacks
Moderate
CVE-2017-12872
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
SimpleSAMLphp XSS Vulnerability
Moderate
CVE-2017-18121
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
Symfony Open Redirect
Moderate
CVE-2018-19790
was published
for
symfony/security
(Composer)
May 14, 2022
Symfony Path Disclosure
Moderate
CVE-2018-19789
was published
for
symfony/form
(Composer)
May 14, 2022
Microweber XSS Vulnerability
Moderate
CVE-2018-19917
was published
for
microweber/microweber
(Composer)
May 14, 2022
phpMyAdmin Local file inclusion through transformation feature
Moderate
CVE-2018-19968
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2018-19970
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Symfony DoS
Moderate
CVE-2018-11386
was published
for
symfony/http-foundation
(Composer)
May 14, 2022
Snipe-IT XSS Vulnerability
Moderate
CVE-2019-10118
was published
for
snipe/snipe-it
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API