GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,081
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,869 advisories
Filter by severity
INTER-Mediator Cross-Site Scripting (XSS)
Moderate
CVE-2017-6484
was published
for
inter-mediator/inter-mediator
(Composer)
May 13, 2022
MAGMI cross-site scripting (XSS)
Moderate
CVE-2015-2068
was published
for
dweeves/magmi
(Composer)
May 13, 2022
Yii Cross-site Scripting Framework vulnerability
Moderate
CVE-2017-11516
was published
for
yiisoft/yii2
(Composer)
May 17, 2022
phpMyAdmin Arbitrary file read vulnerability
Moderate
CVE-2019-6799
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 13, 2022
phpMyAdmin Local file inclusion through transformation feature
Moderate
CVE-2018-19968
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin Cross-site Scripting (XSS) in the import dialog
Moderate
CVE-2018-15605
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin Denial of service (DOS) attack in transformation feature
Moderate
CVE-2016-6618
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin Bypass logout timeout
Moderate
CVE-2016-9851
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Denial of service (DOS) attack with dbase extension
Moderate
CVE-2016-6632
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin allows to detect if user is logged in
Moderate
CVE-2016-6625
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin IPv6 and proxy server IP-based authentication rule circumvention
Moderate
CVE-2016-6624
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting (XSS)
Moderate
CVE-2016-6608
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
qcubed reflected cross-site scripting (XSS) vulnerability
Moderate
CVE-2020-24912
was published
for
qcubed/qcubed
(Composer)
May 24, 2022
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2020-27850
was published
for
wp-premium/gravityforms
(Composer)
May 24, 2022
Gravity Forms stored Cross-Site Scripting (XSS) vulnerability in the survey feature
Moderate
CVE-2020-27852
was published
for
wp-premium/gravityforms
(Composer)
May 24, 2022
Gravity Forms stored HTML injection vulnerability
Moderate
CVE-2020-27851
was published
for
wp-premium/gravityforms
(Composer)
May 24, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5367
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5362
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5363
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5366
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
WPGlobus plugin Stored XSS & CSRF security vulnerability
Moderate
CVE-2018-5364
was published
for
wpglobus/wpglobus
(Composer)
May 14, 2022
Comments plugin stored Cross-site Scripting (XSS) via an asset volume name
Moderate
CVE-2020-13870
was published
for
verbb/comments
(Composer)
May 24, 2022
Comments plugin Cross-Site Request Forgery (CSRF)
Moderate
CVE-2020-13868
was published
for
verbb/comments
(Composer)
May 24, 2022
Comments plugin stored Cross-site Scripting via a guest name
Moderate
CVE-2020-13869
was published
for
verbb/comments
(Composer)
May 24, 2022
SocialNetwork Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2017-7390
was published
for
movingbytes/social-network
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API