GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,685
Maven
5,000+
npm
4,318
NuGet
760
pip
4,092
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,879 advisories
Filter by severity
laracom Cross-site Scripting
Moderate
CVE-2019-15489
was published
for
jsdecena/laracom
(Composer)
May 24, 2022
OpenCart Cross-site Scripting
Moderate
CVE-2020-13980
was published
for
opencart/opencart
(Composer)
May 24, 2022
Cross-site Scripting in phpmyadmin
Moderate
CVE-2022-23808
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 28, 2022
Unrestricted Upload of File with Dangerous Type in unisharp/laravel-filemanager
Moderate
CVE-2021-23814
was published
for
unisharp/laravel-filemanager
(Composer)
Jan 6, 2022
Improper Authentication in phpmyadmin
Moderate
CVE-2022-23807
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 28, 2022
PHP file inclusion via insert tags
Moderate
CVE-2021-37626
was published
for
contao/contao
(Composer)
Aug 23, 2021
Contao Insert tag injection in forms
Moderate
CVE-2020-25768
was published
for
contao/contao
(Composer)
Sep 24, 2020
Information disclosure in the Contao backend
Moderate
CVE-2019-19712
was published
for
contao/contao
(Composer)
Dec 17, 2019
Insert tag injection in the Contao login module
Moderate
CVE-2019-19714
was published
for
contao/contao
(Composer)
Dec 17, 2019
Moodle may display roles to users who don't have access to them
Moderate
CVE-2023-1402
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Moodle vulnerable to SQL Injection
Moderate
CVE-2023-35132
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Moodle vulnerable to Cross-site Scripting
Moderate
CVE-2023-35131
was published
for
moodle/moodle
(Composer)
Jun 22, 2023
Moodle External Control of File Name or Path vulnerability
Moderate
CVE-2023-30943
was published
for
moodle/moodle
(Composer)
May 2, 2023
Moodle arbitrary file read vulnerability
Moderate
CVE-2023-28330
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Moodle vulnerable to Cross-site Scripting
Moderate
CVE-2023-28331
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Moodle vulnerable to Cross-site Scripting when algebra filter enabled but not functional
Moderate
CVE-2023-28332
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Moodle may allow teachers to access the names of users they could not otherwise access
Moderate
CVE-2023-28336
was published
for
moodle/moodle
(Composer)
Mar 23, 2023
Reportico affected by Incorrect Access Control
Moderate
CVE-2023-48865
was published
for
reportico-web/reportico
(Composer)
Apr 12, 2024
Contao: Remember-me tokens will not be cleared after a password change
Moderate
CVE-2024-30262
was published
for
contao/core-bundle
(Composer)
Apr 9, 2024
Contao: Insufficient BBCode sanitizer
Moderate
CVE-2024-28234
was published
for
contao/comments-bundle
(Composer)
Apr 9, 2024
Contao: Cross site scripting in the file manager
Moderate
CVE-2024-28190
was published
for
contao/core-bundle
(Composer)
Apr 9, 2024
Shopware Improper Session Handling in store-api account logout
Moderate
CVE-2024-31447
was published
for
shopware/core
(Composer)
Apr 8, 2024
phpMyFAQ stored Cross-site Scripting at user email
Moderate
CVE-2024-27300
was published
for
phpmyfaq/phpmyfaq
(Composer)
Mar 25, 2024
OpenID Connect Authentication (oidc) Typo3 extension Authentication Bypass
Moderate
CVE-2024-30173
was published
for
causal/oidc
(Composer)
Apr 2, 2024
MediaWiki makeCollapsible allows applying event handler to any CSS selector
Moderate
CVE-2020-10960
was published
for
mediawiki/core
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API