GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2014-3544
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2014-2571
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle's login_as feature leaks information from external repositories
Low
CVE-2013-1835
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Multiple cross-site scripting (XSS) vulnerabilities in the File Picker module
Low
CVE-2013-1833
was published
for
moodle/moodle
(Composer)
May 13, 2022
phpMyAdmin Multiple XSS Vulnerabilities After Inline Editing and Save
Low
CVE-2011-3591
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Multiple XSS Vulnerabilities
Low
CVE-2011-3592
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Typo3 Backend Configuration XSS Vulnerability
Low
CVE-2012-3529
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend XSS Vulnerability
Low
CVE-2012-3528
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Function Menu API XSS Vulnerability
Low
CVE-2012-6148
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend History Module Vulnerable to XSS
Low
CVE-2012-6145
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Backend API XSS Vulnerability
Low
CVE-2012-6147
was published
for
typo3/cms
(Composer)
May 17, 2022
Magento information disclosure vulnerability
Low
CVE-2020-24406
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Information Disclosure vulnerability
Low
CVE-2021-28566
was published
for
magento/community-edition
(Composer)
May 24, 2022
Gila CMS SQL Injection vulnerability
Low
CVE-2020-26625
was published
for
gilacms/gila
(Composer)
Jan 3, 2024
Gila CMS SQL Injection vulnerability
Low
CVE-2020-26624
was published
for
gilacms/gila
(Composer)
Jan 3, 2024
Winter CMS Stored XSS through privileged upload of Media Manager file followed by renaming
Low
CVE-2023-52083
was published
for
winter/wn-system-module
(Composer)
Dec 28, 2023
Winter CMS Stored XSS through Backend ColorPicker FormWidget
Low
CVE-2023-52084
was published
for
winter/wn-backend-module
(Composer)
Dec 28, 2023
Winter CMS Local File Inclusion through Server Side Template Injection
Low
CVE-2023-52085
was published
for
winter/wn-backend-module
(Composer)
Jan 2, 2024
yii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementation
Low
CVE-2023-50708
was published
for
yiisoft/yii2-authclient
(Composer)
Dec 18, 2023
Microweber missing standardized error handling mechanism
Low
CVE-2023-6599
was published
for
microweber/microweber
(Composer)
Dec 8, 2023
Concrete CMS (previously concrete5) is vulnerable to stored XSS in uploaded file and folder names
Low
CVE-2023-28819
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Concrete CMS Cross-site Scripting vulnerability
Low
CVE-2023-48649
was published
for
concrete5/concrete5
(Composer)
Nov 17, 2023
Moodle Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Low
CVE-2023-5551
was published
for
moodle/moodle
(Composer)
Nov 9, 2023
Ibexa ezplatform-kernel download route allows filename change
Low
GHSA-gv2c-5g79-h73c
was published
for
ezsystems/ezplatform-kernel
(Composer)
Nov 3, 2023
Information Disclosure in typo3/cms-install tool
Low
CVE-2023-47126
was published
for
typo3/cms-install
(Composer)
Nov 14, 2023
ProTip!
Advisories are also available from the
GraphQL API