GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,291 advisories
Filter by severity
Centreon Does Not Set HTTPOnly Flag
High
CVE-2019-17104
was published
for
centreon/centreon
(Composer)
May 24, 2022
Subrion CMS CSRF Vulnerability
High
CVE-2017-15063
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Unrestricted Upload of File with Dangerous Type in Croogo
High
CVE-2021-44673
was published
for
croogo/croogo
(Composer)
Mar 11, 2022
Deserialization of Untrusted Data in librenms/librenms
High
CVE-2022-3525
was published
for
librenms/librenms
(Composer)
Nov 20, 2022
Dolibarr ERP and CRM Sensitive Data Disclosure
High
CVE-2017-14240
was published
for
dolibarr/dolibarr
(Composer)
May 17, 2022
Server-Side Request Forgery in snipe/snipe-it
High
CVE-2021-4075
was published
for
snipe/snipe-it
(Composer)
Dec 10, 2021
Centreon SQL Injection
High
CVE-2018-19312
was published
for
centreon/centreon
(Composer)
May 14, 2022
Centreon SQL Injection
High
CVE-2018-19271
was published
for
centreon/centreon
(Composer)
May 14, 2022
PocketMine-MP server crash due to incorrect EC curve used for LoginPacket identityPublicKey
High
GHSA-79rc-jjh6-rc89
was published
for
pocketmine/pocketmine-mp
(Composer)
Sep 14, 2023
DataTable Vulnerable to Cross-Site Scripting
High
CVE-2015-6584
was published
for
datatables
(Composer)
Aug 31, 2020
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000018
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Cross Site Request Forgery in Moodle
High
CVE-2022-0335
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000014
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin CSRF Vulnerability
High
CVE-2017-1000499
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Path traversal in pimcore/pimcore
High
CVE-2021-23340
was published
for
pimcore/pimcore
(Composer)
Feb 25, 2021
Privilage Escalation in moodle
High
CVE-2020-25699
was published
for
moodle/moodle
(Composer)
Mar 29, 2021
Mautic Sessions could be hijacked due to tracking contacts by an auto-incremented ID
High
CVE-2018-10189
was published
for
mautic/core
(Composer)
Jan 19, 2021
Parsedown Class-Name Injection
High
CVE-2019-10905
was published
for
erusev/parsedown
(Composer)
Mar 26, 2022
Disabled users able to log in with third party SSO plugin
High
CVE-2017-1000489
was published
for
mautic/core
(Composer)
Jan 19, 2021
Moodle backs up private files
High
CVE-2012-1156
was published
for
moodle/moodle
(Composer)
Apr 23, 2022
Subrion CMS RCE Vulnerability
High
CVE-2018-19422
was published
for
intelliants/subrion
(Composer)
May 13, 2022
TYPO3 SQL injection vulnerability in the Extbase Framework
High
CVE-2013-1842
was published
for
typo3/cms-core
(Composer)
May 17, 2022
phpMyAdmin Remote Code Execution
High
CVE-2013-3239
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Moodle CSRF Vulnerability
High
CVE-2019-10186
was published
for
moodle/moodle
(Composer)
May 24, 2022
Dolibarr ERP and CRM malicious executable loading
High
CVE-2019-11200
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API