GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,692
Maven
5,000+
npm
4,320
NuGet
760
pip
4,097
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,885 advisories
Filter by severity
TYPO3 Open Redirection vulnerability on the backend
Moderate
CVE-2010-3661
was published
for
typo3/cms-backend
(Composer)
Apr 21, 2022
TYPO3 is vulnerable to Cross-Site Scripting (XSS) on the backend
Moderate
CVE-2010-3660
was published
for
typo3/cms-backend
(Composer)
Apr 21, 2022
TYPO3 vulnerable to Cross-Site Scripting in the textarea view helper
Moderate
CVE-2010-3672
was published
for
typo3/cms-fluid
(Composer)
Apr 21, 2022
Reflected XSS in SilverStripe
Moderate
CVE-2019-19325
was published
for
silverstripe/framework
(Composer)
Feb 24, 2020
SilverStripe GraphQL Server permission checker not inherited by query subclass.
Moderate
CVE-2021-28661
was published
for
silverstripe/graphql
(Composer)
Oct 12, 2021
Symfony Path Disclosure
Moderate
CVE-2018-19789
was published
for
symfony/form
(Composer)
May 14, 2022
Symfony Access Control Vulnerability
Moderate
CVE-2012-6432
was published
for
symfony/symfony
(Composer)
May 17, 2022
Symfony Allows URI Restrictions Bypass Via Double-Encoded String
Moderate
CVE-2012-6431
was published
for
symfony/http-foundation
(Composer)
May 17, 2022
Ability to switch customer email address on account detail page and stay verified
Moderate
CVE-2020-15245
was published
for
sylius/sylius
(Composer)
Oct 19, 2020
Exceptions displayed in non-debug configurations in Symfony
Moderate
CVE-2020-5274
was published
for
symfony/error-handler
(Composer)
Mar 30, 2020
TYPO3 Flow Cross-site scripting (XSS) vulnerability
Moderate
CVE-2013-7082
was published
for
neos/flow
(Composer)
May 17, 2022
Moderate severity vulnerability that affects league/commonmark
Moderate
CVE-2019-10010
was published
for
league/commonmark
(Composer)
Sep 17, 2019
PHP League CommonMark vulnerable to Cross-Site Scripting (XSS)
Moderate
CVE-2018-20583
was published
for
league/commonmark
(Composer)
May 14, 2022
File reference keys leads to incorrect hashes on HMAC algorithms
Moderate
CVE-2021-41106
was published
for
lcobucci/jwt
(Composer)
Sep 29, 2021
Missing Authorization in Drupal
Moderate
CVE-2017-6923
was published
for
drupal/core
(Composer)
Oct 10, 2019
Cross-site Scripting in Drupal Core
Moderate
CVE-2020-13668
was published
for
drupal/core
(Composer)
Feb 12, 2022
DOMPDF Information Disclosure
Moderate
CVE-2014-5011
was published
for
dompdf/dompdf
(Composer)
May 17, 2022
Cross-site Scripting in Contao
Moderate
CVE-2018-10125
was published
for
contao/contao
(Composer)
Feb 10, 2022
phpMyFAQ vulnerable to stored XSS on attachments filename
Moderate
CVE-2024-24574
was published
for
phpmyfaq/phpmyfaq
(Composer)
Feb 5, 2024
Craft CMS Audit Plugin Cross Site Scripting vulnerability
Moderate
CVE-2023-36259
was published
for
superbig/craft-audit
(Composer)
Jan 30, 2024
phpMyFAQ sharing FAQ functionality can easily be abused for phishing purposes
Moderate
CVE-2024-22208
was published
for
phpmyfaq/phpmyfaq
(Composer)
Feb 5, 2024
phpMyFAQ User Removal Page Allows Spoofing Of User Details
Moderate
CVE-2024-22202
was published
for
phpmyfaq/phpmyfaq
(Composer)
Feb 5, 2024
Yii Framework Cross-site Scripting Vulnerability
Moderate
CVE-2015-3397
was published
for
yiisoft/yii2
(Composer)
May 17, 2022
Ckeditor XSS Vulnerability
Moderate
CVE-2018-17960
was published
for
ckeditor
(Composer)
Nov 21, 2018
Typo3 Open Redirect In Frontend Rendering
Moderate
CVE-2014-9508
was published
for
typo3/cms
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API