GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,883 advisories
Filter by severity
Kirby vulnerable to Cross-site scripting (XSS) in the link field "Custom" type
Moderate
CVE-2024-27087
was published
for
getkirby/cms
(Composer)
Feb 26, 2024
Kirby vulnerable to self cross-site scripting (self-XSS) in the URL field
Moderate
CVE-2024-26481
was published
for
getkirby/cms
(Composer)
Feb 26, 2024
Prevent user enumeration using Guard or the new Authenticator-based Security
Moderate
CVE-2021-21424
was published
for
lexik/jwt-authentication-bundle
(Composer)
May 13, 2021
XSS injection in the Grid component of Sylius
Moderate
CVE-2019-12186
was published
for
sylius/grid
(Composer)
Apr 15, 2020
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25874
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
baserCMS Cross-site Scripting vulnerability in Content Management
Moderate
CVE-2024-26128
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
baserCMS OS command injection vulnerability in Installer
Moderate
CVE-2023-51450
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
Path Traversal in TYPO3 Core
Moderate
GHSA-gj48-w74w-8gvm
was published
for
typo3/cms
(Composer)
Feb 22, 2024
Path disclosure in JavaScript variable
Moderate
CVE-2024-26129
was published
for
prestashop/prestashop
(Composer)
Feb 21, 2024
Path Traversal in TYPO3 File Abstraction Layer Storages
Moderate
CVE-2023-30451
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
Joomla! Open Redirect vulnerability
Moderate
CVE-2008-4104
was published
for
joomla/framework
(Composer)
May 2, 2022
Moodle vulnerable to symlink attack
Moderate
CVE-2008-5153
was published
for
moodle/moodle
(Composer)
May 17, 2022
phpMyAdmin Cross-site Scripting In MySQL Table Name
Moderate
CVE-2009-3696
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 2, 2022
Cross-site scripting (XSS) vulnerability in Grav
Moderate
CVE-2023-31506
was published
for
getgrav/grav
(Composer)
Feb 9, 2024
Symfony Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2019-10909
was published
for
drupal/core
(Composer)
Nov 12, 2019
TYPO3 vulnerable to Improper Access Control of Resources Referenced by t3:// URI Scheme
Moderate
CVE-2024-25120
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
TYPO3 Install Tool vulnerable to Information Disclosure of Encryption Key
Moderate
CVE-2024-25119
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
TYPO3 Backend Forms vulnerable to Information Disclosure of Hashed Passwords
Moderate
CVE-2024-25118
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal
Moderate
GHSA-3gjc-mp82-fj4q
was published
for
typo3/cms-core
(Composer)
Dec 25, 2023
•
withdrawn
yuan1994 tpAdmin vulnerable to Server-Side Request Forgery
Moderate
CVE-2023-1971
was published
for
yuan1994/tpadmin
(Composer)
Apr 10, 2023
Drupal core Denial of Service vulnerability
Moderate
GHSA-6ccv-8fgf-cjpw
was published
for
drupal/core
(Composer)
Feb 12, 2024
Moodle Improper Access Control vulnerability
Moderate
CVE-2024-1439
was published
for
moodle/moodle
(Composer)
Feb 12, 2024
Moodle does not properly validate module instance id
Moderate
CVE-2006-4936
was published
for
moodle/moodle
(Composer)
May 1, 2022
Bypass of sitemp access restrictions
Moderate
CVE-2019-8133
was published
for
magento/community-edition
(Composer)
Nov 12, 2019
Magento Cross-site Scripting (XSS)
Moderate
CVE-2019-8153
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API