GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Grav CMS Cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-5233
was published
for
getgrav/grav
(Composer)
May 14, 2022
Drupal cross-site scripting vulnerability
Moderate
CVE-2017-6927
was published
for
drupal/core
(Composer)
May 14, 2022
Drupal external link injection vulnerability
Moderate
CVE-2017-6932
was published
for
drupal/core
(Composer)
May 14, 2022
Drupal cross site scripting vulnerability
Moderate
CVE-2017-6929
was published
for
drupal/core
(Composer)
May 14, 2022
Tiki Wiki CMS XSS Vulnerability
Moderate
CVE-2018-7302
was published
for
tikiwiki/tiki-manager
(Composer)
May 14, 2022
phpMyAdmin Cross-site scripting (XSS) vulnerability in central columns feature
Moderate
CVE-2018-7260
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Dolibarr ERP and CRM contain XSS Vulnerability
Moderate
CVE-2017-1000509
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Cross site scripting in Croogo
Moderate
CVE-2017-1000510
was published
for
croogo/croogo
(Composer)
May 14, 2022
Canvs Canvas XSS Vulnerability
Moderate
CVE-2017-1000507
was published
for
austintoddj/canvas
(Composer)
May 14, 2022
Mautic Cross Site Scripting (XSS) vulnerability
Moderate
CVE-2017-1000506
was published
for
mautic/core
(Composer)
May 14, 2022
SimpleSAMLphp Open redirection protection bypass
Moderate
CVE-2018-6520
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
SilverStripe CSV Excel Macro Injection
Moderate
CVE-2017-18049
was published
for
silverstripe/framework
(Composer)
May 14, 2022
Moodle XSS Vulnerability
Moderate
CVE-2018-1045
was published
for
moodle/moodle
(Composer)
May 14, 2022
Moodle Privilege escalation in quiz web services
Moderate
CVE-2018-1044
was published
for
moodle/moodle
(Composer)
May 14, 2022
Magento Cross-Site Request Forgery (CSRF)
Moderate
CVE-2018-5301
was published
for
magento/community-edition
(Composer)
May 14, 2022
Shopware XSS Vulnerability
Moderate
CVE-2017-15374
was published
for
shopware/shopware
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5366
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5367
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5365
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5364
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5363
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5362
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
eZ Publish Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2017-1000431
was published
for
ezsystems/ezpublish-legacy
(Composer)
May 14, 2022
QuickApps CMS Cross-site Scripting
Moderate
CVE-2017-1000495
was published
for
quickapps/cms
(Composer)
May 14, 2022
Stored XSS in LavaLite 5.2.4
Moderate
CVE-2017-1000467
was published
for
lavalite/cms
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API