GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,291 advisories
Filter by severity
Grav CMS Arbitrary File Deletion
High
CVE-2020-29555
was published
for
getgrav/grav
(Composer)
May 24, 2022
Dolibarr Cross-Site Request Forgery (CSRF)
High
CVE-2019-15062
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Mantis Bug Tracker (MantisBT) allows user account takeover in the signup/reset password process
High
CVE-2024-34077
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2024
PocketMine-MP server crash with certain invalid JSON payloads in `LoginPacket` due to dependency vulnerability (3rd time)
High
GHSA-h6j3-j35f-v2x7
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 6, 2024
PocketMine-MP vulnerable to server crash with certain invalid JSON payloads in `LoginPacket` due to vulnerable dependency
High
GHSA-pqp3-8rrw-g8vm
was published
for
pocketmine/pocketmine-mp
(Composer)
Jun 6, 2023
pygmentize Remote Code Execution
High
GHSA-77mv-mp2j-gxxh
was published
for
3f/pygmentize
(Composer)
May 15, 2024
easyadmin-extension-bundle action case insensitivity
High
GHSA-32rx-xvvr-4xv9
was published
for
alterphp/easyadmin-extension-bundle
(Composer)
May 15, 2024
cart2quote/module-quotation-encoded Remote Code Execution via downloadCustomOptionAction
High
GHSA-pgj4-g5j4-cmfx
was published
for
cart2quote/module-quotation-encoded
(Composer)
May 15, 2024
OpenCFP Framework (Sentry) Account takeover via null password reset codes
High
GHSA-2m5g-8xpw-42vp
was published
for
cartalyst/sentry
(Composer)
May 15, 2024
Magento SQL injection vulnerability
High
CVE-2019-8130
was published
for
magento/community-edition
(Composer)
May 24, 2022
contao/core PHP object injection vulnerability allows for arbitrary code execution
High
GHSA-wq43-8r5p-w3mc
was published
for
contao/core
(Composer)
May 15, 2024
Doctrine DBAL SQL injection possibility
High
GHSA-76w8-mqx4-wjrf
was published
for
doctrine/dbal
(Composer)
May 15, 2024
Grav Vulnerable to Arbitrary File Read to Account Takeover
High
CVE-2024-34082
was published
for
getgrav/grav
(Composer)
May 15, 2024
doctrine/orm Regression in Query Parenthesis can have Security Implications
High
GHSA-vjrg-wpm8-rhrw
was published
for
doctrine/orm
(Composer)
May 15, 2024
Guard bypass in Eloquent models affecting Laravel illuminate database component
High
CVE-2020-24940
was published
for
illuminate/database
(Composer)
May 24, 2022
Drupal core Multiple vulnerabilities due to the use of the third-party library Archive_Tar
High
GHSA-98h9-727m-44qv
was published
for
drupal/core
(Composer)
May 15, 2024
Drupal core Arbitrary PHP code execution
High
GHSA-gxxj-g9v8-w28p
was published
for
drupal/core
(Composer)
May 15, 2024
Drupal core Multiple vulnerabilities due to the use of the third-party library Archive_Tar
High
GHSA-m9fv-whq2-6wmc
was published
for
drupal/drupal
(Composer)
May 15, 2024
Drupal core Arbitrary PHP code execution
High
GHSA-j66p-fvp2-fxhj
was published
for
drupal/drupal
(Composer)
May 15, 2024
Path Traversal within joomla/archive tar class
High
CVE-2022-23793
was published
for
joomla/archive
(Composer)
Mar 31, 2022
Cross-site Scripting (XSS) in DemoBundle/ezdemo bundled VideoJS
High
GHSA-jq9q-6p42-qpr7
was published
for
ezsystems/ezdemo-ls-extension
(Composer)
May 15, 2024
Cross-site Scripting (XSS) in DemoBundle/ezdemo bundled VideoJS
High
GHSA-8c85-4rr5-chr4
was published
for
ezsystems/demobundle
(Composer)
May 15, 2024
Cross-site Scripting in eZFind spellcheck
High
GHSA-9cq2-pcgr-8h62
was published
for
ezsystems/ezfind-ls
(Composer)
May 15, 2024
eZ Platform Password reset vulnerability
High
GHSA-cg84-55jx-4237
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
May 15, 2024
eZ Platform Admin UI Cross-site Scripting vulnerability
High
GHSA-q73v-79x3-jv2w
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
May 15, 2024
ProTip!
Advisories are also available from the
GraphQL API