GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,290 advisories
Filter by severity
BuddyPress privilege escalation via REST API
High
CVE-2021-21389
was published
for
buddypress/buddypress
(Composer)
Oct 6, 2021
Arbitrary Code Execution in feehi/cms
High
CVE-2020-21322
was published
for
feehi/cms
(Composer)
Sep 20, 2021
Cross-site Scripting in snipe/snipe-it
High
CVE-2021-3961
was published
for
snipe/snipe-it
(Composer)
Nov 23, 2021
Data Flow Sanitation Issue Fix
High
CVE-2021-32759
was published
for
openmage/magento-lts
(Composer)
Aug 30, 2021
Improper Resource Shutdown or Release in TYPO3 extension
High
CVE-2021-38623
was published
for
webcoast/deferred-image-processing
(Composer)
Aug 30, 2021
OS Command Injection in Centreon
High
CVE-2020-22345
was published
for
centreon/centreon
(Composer)
Sep 2, 2021
raspap-webgui in RaspAP 2.6.6 allows attackers to execute commands as root because of the insecure sudoers permissions.
High
CVE-2021-38557
was published
for
billz/raspap-webgui
(Composer)
Sep 2, 2021
Command Injection in RaspAP 2.6.6
High
CVE-2021-38556
was published
for
billz/raspap-webgui
(Composer)
Sep 2, 2021
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
High
CVE-2021-3915
was published
for
ssddanbrown/bookstack
(Composer)
Nov 15, 2021
Insecure Inherited Permissions in neoan3-apps/template
High
CVE-2021-41170
was published
for
neoan3-apps/template
(Composer)
Nov 10, 2021
Cross-Site Scripting via SVG media files
High
CVE-2021-37710
was published
for
shopware/core
(Composer)
Aug 23, 2021
Cross-Site Request Forgery in GilaCMS
High
CVE-2020-20693
was published
for
gilacms/gila
(Composer)
Sep 30, 2021
CSV Injection Vulnerability
High
CVE-2021-41824
was published
for
craftcms/cms
(Composer)
Oct 18, 2021
Improper Neutralization of Text-Values in Object Version Preview
High
CVE-2021-39166
was published
for
pimcore/pimcore
(Composer)
Sep 1, 2021
Improper Encoding or Escaping of Output in Asset Metadata Component
High
CVE-2021-39170
was published
for
pimcore/pimcore
(Composer)
Sep 1, 2021
Sensitive Data Exposure in miniorange_saml
High
CVE-2021-36786
was published
for
miniorange/miniorange-saml
(Composer)
Sep 1, 2021
Layout XML Arbitrary Code Fix
High
CVE-2021-32758
was published
for
openmage/magento-lts
(Composer)
Aug 30, 2021
Improper Input Validation in Centreon Web
High
CVE-2019-16405
was published
for
centreon/centreon
(Composer)
Jul 28, 2021
Authenticated server-side request forgery in file upload via URL.
High
CVE-2021-37711
was published
for
shopware/core
(Composer)
Aug 23, 2021
Directory Traversal in Archive_Tar
High
CVE-2021-32610
was published
for
pear/archive_tar
(Composer)
Aug 9, 2021
Missing Authorization in TeamPass
High
CVE-2020-11671
was published
for
nilsteampassnet/teampass
(Composer)
Jul 26, 2021
Exposure of Resource to Wrong Sphere in LibreNMS
High
CVE-2020-15877
was published
for
librenms/librenms
(Composer)
Sep 8, 2021
Cross-Site Request Forgery in forkcms
High
CVE-2020-23264
was published
for
forkcms/forkcms
(Composer)
Jun 22, 2021
Arbitrary file upload in Fork CMS
High
CVE-2021-28931
was published
for
forkcms/forkcms
(Composer)
Sep 8, 2021
Incorrect Authorization in TeamPass
High
CVE-2020-12477
was published
for
nilsteampassnet/teampass
(Composer)
Jul 26, 2021
ProTip!
Advisories are also available from the
GraphQL API