GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,883 advisories
Filter by severity
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8142
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Unrestricted file upload vulnerability
Moderate
CVE-2019-8140
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8138
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8139
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8132
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8131
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Insufficient Logging
Moderate
CVE-2019-8124
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8120
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Weak Cryptography
Moderate
CVE-2019-8118
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8115
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Weak PRNG
Moderate
CVE-2019-8113
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Arbitrary File Deletion
Moderate
CVE-2019-8107
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition XSS Vulnerability
Moderate
CVE-2019-8092
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Arbitrary File Deletion
Moderate
CVE-2019-8090
was published
for
magento/community-edition
(Composer)
May 24, 2022
Cross-site Scripting in SilverStripe Framework
Moderate
CVE-2021-36150
was published
for
silverstripe/admin
(Composer)
Oct 12, 2021
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in typo3/cms-form
Moderate
CVE-2021-21358
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Cleartext storage of session identifier
Moderate
CVE-2021-21339
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Cross-Site Scripting in Content Preview
Moderate
CVE-2021-21340
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Cross-Site Scripting in Content Preview (CType menu)
Moderate
CVE-2021-21370
was published
for
typo3/cms
(Composer)
Mar 23, 2021
Record titles for restricted records can be viewed if exposed by GridFieldAddExistingAutocompleter
Moderate
CVE-2023-48714
was published
for
silverstripe/framework
(Composer)
Jan 23, 2024
ConcreteCMS Cross-site Scripting vulnerability
Moderate
CVE-2023-44764
was published
for
concrete5/concrete5
(Composer)
Oct 6, 2023
Moodle allows discovery of an author's username
Moderate
CVE-2014-3617
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Moderate
CVE-2014-0218
was published
for
moodle/moodle
(Composer)
May 13, 2022
MediaWiki allows a denial of service
Moderate
CVE-2021-41800
was published
for
mediawiki/core
(Composer)
May 24, 2022
browsershot local file inclusion vulnerability
Moderate
CVE-2020-7790
was published
for
spatie/browsershot
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API