GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,700
Maven
5,000+
npm
4,327
NuGet
761
pip
4,099
Pub
12
RubyGems
958
Rust
1,064
Swift
45
Unreviewed advisories
All unreviewed
5,000+
2,886 advisories
Filter by severity
Moodle Authentication Bypass in Question-Bank
Moderate
CVE-2012-2356
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Users Can Bypass Deleted Status
Moderate
CVE-2012-0797
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Allows Unauthenticated Dropbox Access
Moderate
CVE-2012-5471
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Authentication Bypass in File Upload
Moderate
CVE-2012-3387
was published
for
moodle/moodle
(Composer)
May 13, 2022
PHPEMS Deserialization of Untrusted Data vulnerability
Moderate
CVE-2023-6654
was published
for
phpems/phpems
(Composer)
Dec 10, 2023
Magento Improper Access Control vulnerability
Moderate
CVE-2022-34259
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2022-34258
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento stored Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2022-34257
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
class.upload.php allows cross-site scripting attacks via uploaded files
Moderate
CVE-2023-6551
was published
for
verot/class.upload.php
(Composer)
Jan 4, 2024
Magento Cross-Site Request Forgery (CSRF)
Moderate
CVE-2018-5301
was published
for
magento/community-edition
(Composer)
May 14, 2022
Magento observable timing discrepancy vulnerability
Moderate
CVE-2020-9690
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento security mitigation bypass vulnerability
Moderate
CVE-2020-9692
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento incorrect permissions vulnerability in the Inventory module
Moderate
CVE-2020-24405
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-9665
was published
for
magento/core
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-3715
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-3758
was published
for
magento/community-edition
(Composer)
May 24, 2022
Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access GDPR extracts
Moderate
CVE-2024-21667
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jan 10, 2024
Pimcore Customer Data Framework Improper Access Control allows unprivileged user to access customers duplicates list
Moderate
CVE-2024-21666
was published
for
pimcore/customer-management-framework-bundle
(Composer)
Jan 10, 2024
Pimcore Ecommerce Framework Bundle Improper Access Control allows unprivileged user to access back-office orders list
Moderate
CVE-2024-21665
was published
for
pimcore/ecommerce-framework-bundle
(Composer)
Jan 10, 2024
Magento XSS Vulnerability
Moderate
CVE-2019-8227
was published
for
magento/core
(Composer)
May 24, 2022
Wallabag cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-11352
was published
for
wallabag/wallabag
(Composer)
May 14, 2022
YOURLS Stored Cross Site Scripting (XSS)
Moderate
CVE-2020-27388
was published
for
yourls/yourls
(Composer)
May 24, 2022
Magento Unauthorized access to restricted resources
Moderate
CVE-2021-28563
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Path Traversal
Moderate
CVE-2020-3717
was published
for
magento/community-edition
(Composer)
May 24, 2022
WooCommerce Incorrect Authorization
Moderate
CVE-2020-29156
was published
for
woocommerce/woocommerce
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API