Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,886 advisories

Loading
Moodle reveals absolute path in exception message Moderate
CVE-2013-1831 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Credited to MarkLee131
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter Moderate
CVE-2021-21029 was published for magento/community-edition (Composer) May 24, 2022
Drupal Denial of Service vulnerability Moderate
CVE-2024-22362 was published for drupal/core (Composer) Jan 16, 2024
TYPO3 is vulnerable to Information Disclosure in the HTML mailing API Moderate
CVE-2010-3673 was published for typo3/cms-core (Composer) Apr 21, 2022
Silverstripe CMS Arbitrary Code Execution Moderate
CVE-2011-4962 was published for silverstripe/cms (Composer) May 17, 2022
Moodle allows remote attackers to read arbitrary files Moderate
CVE-2014-3542 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Credited to MarkLee131
Moodle does not enforce the forceloginforprofiles setting Moderate
CVE-2013-1830 was published for moodle/moodle (Composer) May 13, 2022
MarkLee131
Credited to MarkLee131
Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled Moderate
CVE-2021-24323 was published for woocommerce/woocommerce (Composer) May 24, 2022
Stored cross site scripting via container name Moderate
CVE-2023-28471 was published for concrete5/concrete5 (Composer) Apr 28, 2023
Broken Access Control order API in Shopware Moderate
CVE-2024-22407 was published for shopware/core (Composer) Jan 17, 2024
Moodle CRLF Injection Vulnerability in Calendar Component Moderate
CVE-2011-4203 was published for moodle/moodle (Composer) May 13, 2022
Moodle Incorrect Default Settings Moderate
CVE-2011-4285 was published for moodle/moodle (Composer) May 13, 2022
Moodle vulnerable to XSS via bundled spikephpcoverage library Moderate
CVE-2011-4280 was published for moodle/moodle (Composer) May 13, 2022
Moodle Open Redirect in Calendar Set Page Moderate
CVE-2011-4582 was published for moodle/moodle (Composer) May 13, 2022
Moodle does not properly restrict access to category and course data Moderate
CVE-2011-4300 was published for moodle/moodle (Composer) May 13, 2022
Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory Moderate
CVE-2011-4293 was published for moodle/moodle (Composer) May 13, 2022
Moodle XSS Vulnerability Moderate
CVE-2011-4306 was published for moodle/moodle (Composer) May 13, 2022
Moodle Allows Modification of Constants Moderate
CVE-2011-4301 was published for moodle/moodle (Composer) May 13, 2022
Moodle XSS In Tag Autocomplete functionality Moderate
CVE-2011-4278 was published for moodle/moodle (Composer) May 13, 2022
Moodle Open Redirect Via Error Messages Moderate
CVE-2011-4294 was published for moodle/moodle (Composer) May 13, 2022
Neos CMS Cross Site Scripting vulnerability Moderate
CVE-2023-37611 was published for neos/media-browser (Composer) Sep 19, 2023
kdambekalns dlubitz
Credited to kdambekalns and dlubitz
EC-CUBE XSS Vulnerabilities Moderate
CVE-2011-0451 was published for ec-cube/ec-cube (Composer) May 17, 2022
BaserCMS privilege escallation Moderate
CVE-2011-2674 was published for baserproject/basercms (Composer) May 13, 2022
phpMyAdmin Directory Traversal Vulnerability Moderate
CVE-2011-2718 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
phpMyAdmin Open Redirect in redirector Moderate
CVE-2011-1941 was published for phpmyadmin/phpmyadmin (Composer) May 17, 2022
ProTip! Advisories are also available from the GraphQL API