GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,869 advisories
Filter by severity
EC-CUBE Cross-site scripting vulnerability
Moderate
CVE-2021-20750
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
EC-CUBE Cross-site scripting vulnerability
Moderate
CVE-2021-20717
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
EC-CUBE Improper Restriction of Rendered UI Layers or Frames
Moderate
CVE-2020-5679
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
BuddyPress Docs plugin Improper Privilege Management
Moderate
CVE-2017-6954
was published
for
buddypress/buddypress
(Composer)
May 13, 2022
ezplatform-admin-ui Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2019-12139
was published
for
ezsystems/ezplatform-admin-ui
(Composer)
May 24, 2022
MunkiReport munki_facts module Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2020-15881
was published
for
munkireport/munki_facts
(Composer)
May 24, 2022
TeamPass Cross-Site Scripting (XSS)
Moderate
CVE-2017-15278
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
Grav CMS Cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-5233
was published
for
getgrav/grav
(Composer)
May 14, 2022
TeamPass Improper Privilege Management
Moderate
CVE-2017-15052
was published
for
nilsteampassnet/teampass
(Composer)
May 13, 2022
TeamPass Improper Privilege Management
Moderate
CVE-2017-15053
was published
for
nilsteampassnet/teampass
(Composer)
May 13, 2022
TeamPass stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2017-15051
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
TeamPass Stored Cross-site Scripting
Moderate
CVE-2019-17204
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2022
TeamPass Stored Cross-site Scripting
Moderate
CVE-2019-17203
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2022
TeamPass Stored Cross-site Scripting
Moderate
CVE-2019-17205
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2022
TeamPass Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2019-16904
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2022
TeamPass Cross-site Scripting (XSS)
Moderate
CVE-2019-12950
was published
for
nilsteampassnet/teampass
(Composer)
May 24, 2022
Grav CMS Local File Injection
Moderate
CVE-2020-29556
was published
for
getgrav/grav
(Composer)
May 24, 2022
SunHater KCFinder cross-site scripting (XSS) vulnerability in upload.php
Moderate
CVE-2019-14315
was published
for
sunhater/kcfinder
(Composer)
May 24, 2022
Dolibarr allows password changes without supplying the current password
Moderate
CVE-2017-8879
was published
for
dolibarr/dolibarr
(Composer)
May 13, 2022
Dolibarr Stored Cross-site Scripting in expensereport/card.php
Moderate
CVE-2018-16808
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Dolibarr stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-19992
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Dolibarr reflected cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-19993
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Dolibarr stored cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-19995
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Unauthenticated Sensitive Information Disclosure vulnerability
Moderate
CVE-2022-34867
was published
for
libreform/libreform
(Composer)
Sep 7, 2022
Dolibarr cross-site scripting (XSS) vulnerability
Moderate
CVE-2017-14239
was published
for
dolibarr/dolibarr
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API