GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,121
NuGet
735
pip
3,942
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
174 advisories
Filter by severity
phpMyAdmin Improper Input Validation
Moderate
CVE-2016-2562
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to spoof content via the url parameter
High
CVE-2015-7873
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 OpenID extension Open redirect vulnerability
Moderate
CVE-2013-7079
was published
for
friendsoftypo3/openid
(Composer)
May 17, 2022
XMPP Clients User Impersonation Vulnerability in Movim Moxl
Moderate
CVE-2017-5605
was published
for
movim/moxl
(Composer)
May 17, 2022
Laravel does not properly constrain the host portion of a password-reset URL
Moderate
CVE-2017-9303
was published
for
illuminate/auth
(Composer)
May 17, 2022
phpMyAdmin DoS Vulnerability
Moderate
CVE-2016-6623
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Denial of Service (DoS)
Moderate
CVE-2016-9860
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2016-9863
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Cookie attribute injection attack
High
CVE-2017-1000016
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
Moderate
CVE-2011-0986
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 Path Traversal vulnerability
Moderate
CVE-2010-5099
was published
for
typo3/cms
(Composer)
May 17, 2022
GeniXCMS denial of service (account blockage)
Moderate
CVE-2017-14231
was published
for
genix/cms
(Composer)
May 17, 2022
CodeIgniter HTTP Header Injection
High
CVE-2017-1000247
was published
for
codeigniter4/framework
(Composer)
May 17, 2022
Typo3 Host Header Spoofing Vulnerability
Moderate
CVE-2014-3941
was published
for
typo3/cms
(Composer)
May 14, 2022
Moodle Portfolio script allows instantiation of class chosen by user
High
CVE-2018-1137
was published
for
moodle/moodle
(Composer)
May 14, 2022
Shopware RCE Vulnerability
Critical
CVE-2016-3109
was published
for
shopware/shopware
(Composer)
May 14, 2022
Symfony SSRF Vulnerability via Form Component
Moderate
CVE-2017-16790
was published
for
symfony/form
(Composer)
May 14, 2022
Symfony Host Header Injection
High
CVE-2018-14774
was published
for
symfony/symfony
(Composer)
May 14, 2022
Elefant CMS Improper Input Validation
Critical
CVE-2018-15601
was published
for
elefant/cms
(Composer)
May 14, 2022
CakePHP allows remote attackers to spoof their IP
High
CVE-2016-4793
was published
for
cakephp/cakephp
(Composer)
May 14, 2022
SabreDAV Directory Traversal vulnerability
Moderate
CVE-2013-1939
was published
for
sabre/dav
(Composer)
May 14, 2022
Drupal Core Remote Code Execution Vulnerability
Critical
CVE-2018-7600
was published
for
drupal/core
(Composer)
May 14, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000014
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000018
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
SimpleSAMLphp InfoCard module Incorrect signature verification
High
CVE-2017-12874
was published
for
simplesamlphp/simplesamlphp-module-infocard
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API