Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
Moodle Setting for blocked hosts list can be bypassed with multiple A record hostnames Moderate
CVE-2018-1043 was published for moodle/moodle (Composer) May 13, 2022
Moodle Improper Privilege Management Moderate
CVE-2018-1134 was published for moodle/moodle (Composer) May 13, 2022
Moodle Cross-site Scripting Moderate
CVE-2018-1136 was published for moodle/moodle (Composer) May 13, 2022
Paymorrow Improper Input Validation vulnerability Moderate
CVE-2018-14020 was published for oxid-esales/paymorrow-module (Composer) May 13, 2022
Showdoc Unauthenticated Access Moderate
CVE-2018-19620 was published for showdoc/showdoc (Composer) May 13, 2022
cx-aditya-dixit
Credited to cx-aditya-dixit
Kirby XSS Vulnerability Moderate
CVE-2017-16807 was published for getkirby/cms (Composer) May 14, 2022
Centreon XSS Vulnerability Moderate
CVE-2018-19311 was published for centreon/centreon (Composer) May 14, 2022
Centreon XSS Vulnerability Moderate
CVE-2018-19280 was published for centreon/centreon (Composer) May 14, 2022
Centreon Cross-site Scripting Vulnerability Moderate
CVE-2015-7672 was published for centreon/centreon (Composer) May 14, 2022
Moodle SSRF Vulnerability Moderate
CVE-2018-1042 was published for moodle/moodle (Composer) May 14, 2022
Enhanced Image plugin for CKEditor is vulnerable to Cross-site scripting (XSS) Moderate
CVE-2018-9861 was published for ckeditor-dev (Composer) May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks Moderate
CVE-2014-2683 was published for zendframework/zendframework1 (Composer) May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks Moderate
CVE-2014-2681 was published for zendframework/zendframework1 (Composer) May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks Moderate
CVE-2014-2682 was published for zendframework/zendframework1 (Composer) May 14, 2022
Shopware XXE Vulnerability Moderate
CVE-2017-18357 was published for shopware/shopware (Composer) May 14, 2022
SimpleSAMLphp allows timing side-channel attacks Moderate
CVE-2017-12872 was published for simplesamlphp/simplesamlphp (Composer) May 14, 2022
SimpleSAMLphp XSS Vulnerability Moderate
CVE-2017-18121 was published for simplesamlphp/simplesamlphp (Composer) May 14, 2022
Symfony Open Redirect Moderate
CVE-2018-19790 was published for symfony/security (Composer) May 14, 2022
Symfony Path Disclosure Moderate
CVE-2018-19789 was published for symfony/form (Composer) May 14, 2022
Microweber XSS Vulnerability Moderate
CVE-2018-19917 was published for microweber/microweber (Composer) May 14, 2022
phpMyAdmin Local file inclusion through transformation feature Moderate
CVE-2018-19968 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
phpMyAdmin Cross-site Scripting (XSS) vulnerability Moderate
CVE-2018-19970 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
Elgg open redirect Moderate
CVE-2019-11016 was published for elgg/elgg (Composer) May 14, 2022
Symfony DoS Moderate
CVE-2018-11386 was published for symfony/http-foundation (Composer) May 14, 2022
Snipe-IT XSS Vulnerability Moderate
CVE-2019-10118 was published for snipe/snipe-it (Composer) May 14, 2022
ProTip! Advisories are also available from the GraphQL API