GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,291 advisories
Filter by severity
Pimcore SQL Injection in Admin Grid Filter API through Multiselect::getFilterConditionExt()
High
CVE-2023-47637
was published
for
pimcore/pimcore
(Composer)
Nov 15, 2023
Cross Site Request Forgery in SwiftyEdit
High
CVE-2023-47350
was published
for
swiftyedit/swiftyedit
(Composer)
Nov 22, 2023
Cross-site Scripting via uploaded assets
High
CVE-2023-48701
was published
for
statamic/cms
(Composer)
Nov 22, 2023
phpseclib vulnerable to denial of service
High
CVE-2023-49316
was published
for
phpseclib/phpseclib
(Composer)
Nov 27, 2023
Pimcore Admin UI has Two Factor Authentication disabled for non admin security firewalls
High
CVE-2023-49075
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Nov 27, 2023
OroPlatform vulnerable to path traversal during temporary file manipulations
High
CVE-2022-41951
was published
for
oro/platform
(Composer)
Nov 27, 2023
Validation of SignedInfo
High
CVE-2023-49087
was published
for
simplesamlphp/saml2
(Composer)
Nov 28, 2023
Microweber file upload vulnerability
High
CVE-2023-49052
was published
for
microweber/microweber
(Composer)
Nov 30, 2023
ThinkAdmin arbitrary file upload vulnerability
High
CVE-2023-48966
was published
for
zoujingli/thinkadmin
(Composer)
Dec 4, 2023
Microweber allows a remote attacker to obtain sensitive information via the HTTP GET method
High
CVE-2023-48122
was published
for
microweber/microweber
(Composer)
Dec 8, 2023
Magento LTS vulnerable to Stored XSS via TinyMCE WYSIWYG Editor
High
GHSA-9j5w-2cqc-cwj9
was published
for
openmage/magento-lts
(Composer)
Dec 8, 2023
Configuration Injection in extension "Direct Mail" (direct_mail)
High
CVE-2023-50461
was published
for
directmailteam/direct-mail
(Composer)
Dec 13, 2023
MainWP Dashboard SQL Command Injection vulnerability
High
CVE-2023-38519
was published
for
mainwp/mainwp
(Composer)
Dec 20, 2023
PrestaShop some attribute not escaped in Validate::isCleanHTML method
High
CVE-2024-21627
was published
for
prestashop/prestashop
(Composer)
Jan 3, 2024
Froxlor username/surname AND company field Bypass
High
CVE-2023-50256
was published
for
froxlor/froxlor
(Composer)
Jan 4, 2024
WWBN AVideo Improper Restriction of Excessive Authentication Attempts vulnerability
High
CVE-2023-49810
was published
for
wwbn/avideo
(Composer)
Jan 10, 2024
SQL Injection in Admin download files as zip
High
CVE-2024-23646
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 24, 2024
Host header injection in the password reset
High
CVE-2024-23648
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Jan 24, 2024
Arbitrary Code Execution in Processwire
High
CVE-2023-24676
was published
for
processwire/processwire
(Composer)
Jan 24, 2024
livewire Cross-Site Request Forgery vulnerability
High
CVE-2024-22859
was published
for
livewire/livewire
(Composer)
Feb 1, 2024
•
withdrawn
Statmic CMS vulnerable to account takeover via XSS and password reset link
High
CVE-2024-24570
was published
for
statamic/cms
(Composer)
Feb 1, 2024
PHPMailer Shell command injection
High
CVE-2007-3215
was published
for
phpmailer/phpmailer
(Composer)
Feb 2, 2024
Composer code execution and possible privilege escalation via compromised InstalledVersions.php or installed.php
High
CVE-2024-24821
was published
for
composer/composer
(Composer)
Feb 8, 2024
October CMS Cross-site Scripting vulnerability
High
CVE-2023-25365
was published
for
october/october
(Composer)
Feb 9, 2024
ProTip!
Advisories are also available from the
GraphQL API