Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,291 advisories

Loading
Cross Site Scripting in thorsten/phpmyfaq High
CVE-2023-2550 was published for thorsten/phpmyfaq (Composer) May 5, 2023
Improper Privilege Management in microweber High
CVE-2023-2240 was published for microweber/microweber (Composer) Apr 22, 2023
Dolibarr Improper Input Validation vulnerability High
CVE-2023-4197 was published for dolibarr/dolibarr (Composer) Nov 1, 2023
phpMyFAQ Cross-site Scripting vulnerability High
CVE-2023-5864 was published for thorsten/phpmyfaq (Composer) Oct 31, 2023
Cross-Site Request Forgery (CSRF) in snipe/snipe-it High
CVE-2023-5511 was published for snipe/snipe-it (Composer) Oct 11, 2023
Duplicate Advisory: elFinder vulnerable to path traversal in LocalVolumeDriver connector High
GHSA-3p2q-mh7q-9pxj was published for studio-42/elfinder (Composer) Jun 19, 2023 withdrawn
Cockpit Cross-site Scripting vulnerability High
CVE-2023-4433 was published for cockpit-hq/cockpit (Composer) Aug 19, 2023
Cockpit Cross-site Scripting vulnerability High
CVE-2023-4432 was published for cockpit-hq/cockpit (Composer) Aug 19, 2023
GilaCMS Cross Site Request Forgery vulnerability High
CVE-2020-20726 was published for gilacms/gila (Composer) Jun 20, 2023
ipandlanguageredirect extension vulnerable to SQL Injection High
CVE-2023-35782 was published for in2code/ipandlanguageredirect (Composer) Jun 16, 2023
phpMyAdmin Cryptographic Vulnerability High
CVE-2016-1927 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account High
CVE-2023-30860 was published for wwbn/avideo (Composer) May 1, 2023
gonzxph
pimcore/customer-management-framework-bundle has SQL Injection vulnerability in Segment Assignment query High
CVE-2023-2756 was published for pimcore/customer-management-framework-bundle (Composer) May 17, 2023
JoMC98
Drupal core arbitrary PHP code execution High
CVE-2022-25277 was published for drupal/core (Composer) Aug 6, 2022
Drupal core Information Disclosure vulnerability High
CVE-2022-25275 was published for drupal/core (Composer) Aug 6, 2022
Embedding untrusted input inside CSV files leads to Formula Injection/CSV Injection High
CVE-2023-2629 was published for pimcore/customer-management-framework-bundle (Composer) May 11, 2023
sampritdas8
Improper input validation in Drupal core High
CVE-2022-25273 was published for drupal/core (Composer) Apr 26, 2023
Cockpit Cross-site Scripting vulnerability High
CVE-2023-4395 was published for cockpit-hq/cockpit (Composer) Aug 17, 2023
LibreNMS Cross-site Scripting vulnerability High
CVE-2023-4347 was published for librenms/librenms (Composer) Aug 15, 2023
Cockpit Cross-site Scripting vulnerability High
CVE-2023-4321 was published for cockpit-hq/cockpit (Composer) Aug 14, 2023
Insufficient Session Expiration after a password change High
CVE-2023-38489 was published for getkirby/cms (Composer) Jul 28, 2023
5hank4r
Dolibarr vulnerable to unauthenticated database access High
CVE-2023-33568 was published for dolibarr/dolibarr (Composer) Jun 13, 2023
RaspAP raspap-webgui Command Injection vulnerability High
CVE-2023-30260 was published for billz/raspap-webgui (Composer) Jun 23, 2023
Command injection in pagekit High
CVE-2023-41005 was published for pagekit/pagekit (Composer) Aug 29, 2023
TeamPass Cross-site Scripting vulnerability High
CVE-2023-3531 was published for nilsteampassnet/teampass (Composer) Jul 6, 2023
ProTip! Advisories are also available from the GraphQL API