GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,698
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Moodle reveals absolute path in exception message
Moderate
CVE-2013-1831
was published
for
moodle/moodle
(Composer)
May 13, 2022
Magento Reflected Cross-site Scripting vulnerability via 'file' parameter
Moderate
CVE-2021-21029
was published
for
magento/community-edition
(Composer)
May 24, 2022
Drupal Denial of Service vulnerability
Moderate
CVE-2024-22362
was published
for
drupal/core
(Composer)
Jan 16, 2024
TYPO3 is vulnerable to Information Disclosure in the HTML mailing API
Moderate
CVE-2010-3673
was published
for
typo3/cms-core
(Composer)
Apr 21, 2022
Silverstripe CMS Arbitrary Code Execution
Moderate
CVE-2011-4962
was published
for
silverstripe/cms
(Composer)
May 17, 2022
Moodle allows remote attackers to read arbitrary files
Moderate
CVE-2014-3542
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not enforce the forceloginforprofiles setting
Moderate
CVE-2013-1830
was published
for
moodle/moodle
(Composer)
May 13, 2022
Woocommerce Cross-site Scripting via Additional tax classes field when taxes are enabled
Moderate
CVE-2021-24323
was published
for
woocommerce/woocommerce
(Composer)
May 24, 2022
Stored cross site scripting via container name
Moderate
CVE-2023-28471
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Broken Access Control order API in Shopware
Moderate
CVE-2024-22407
was published
for
shopware/core
(Composer)
Jan 17, 2024
Moodle CRLF Injection Vulnerability in Calendar Component
Moderate
CVE-2011-4203
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Incorrect Default Settings
Moderate
CVE-2011-4285
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to XSS via bundled spikephpcoverage library
Moderate
CVE-2011-4280
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Open Redirect in Calendar Set Page
Moderate
CVE-2011-4582
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly restrict access to category and course data
Moderate
CVE-2011-4300
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Double-Caches Content, Potentially Writing to a File System's Tmp Directory
Moderate
CVE-2011-4293
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle XSS Vulnerability
Moderate
CVE-2011-4306
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Allows Modification of Constants
Moderate
CVE-2011-4301
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle XSS In Tag Autocomplete functionality
Moderate
CVE-2011-4278
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Open Redirect Via Error Messages
Moderate
CVE-2011-4294
was published
for
moodle/moodle
(Composer)
May 13, 2022
Neos CMS Cross Site Scripting vulnerability
Moderate
CVE-2023-37611
was published
for
neos/media-browser
(Composer)
Sep 19, 2023
EC-CUBE XSS Vulnerabilities
Moderate
CVE-2011-0451
was published
for
ec-cube/ec-cube
(Composer)
May 17, 2022
BaserCMS privilege escallation
Moderate
CVE-2011-2674
was published
for
baserproject/basercms
(Composer)
May 13, 2022
phpMyAdmin Directory Traversal Vulnerability
Moderate
CVE-2011-2718
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Open Redirect in redirector
Moderate
CVE-2011-1941
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API