GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,122
NuGet
735
pip
3,943
Pub
12
RubyGems
945
Rust
1,020
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
phpMyAdmin full path disclosure vulnerability
Moderate
CVE-2016-5730
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5705
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5701
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting
Moderate
CVE-2016-5733
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin XSS Vulnerability
Moderate
CVE-2016-2040
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin Implementation XSS Vulnerability on Server Monitor Page
Moderate
CVE-2014-8326
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
Pimcore XSS Vulnerability
Moderate
CVE-2018-14059
was published
for
pimcore/pimcore
(Composer)
May 14, 2022
Subrion Cross-site scripting (XSS) vulnerability
Moderate
CVE-2017-10795
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Subrion CMS Cross-site Scripting
Moderate
CVE-2018-14840
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Subrion CMS Cross-site scripting in search
Moderate
CVE-2014-9120
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Subrion CMS Stored Cross-site Scripting (XSS)
Moderate
CVE-2018-15563
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Subrion Cross-site Scripting (XSS)
Moderate
CVE-2018-16327
was published
for
intelliants/subrion
(Composer)
May 14, 2022
Wallabag cross-site scripting (XSS) vulnerability
Moderate
CVE-2018-11352
was published
for
wallabag/wallabag
(Composer)
May 14, 2022
Smarty Path Traversal Vulnerability
Moderate
CVE-2018-16831
was published
for
smarty/smarty
(Composer)
May 14, 2022
Coaster CMS Stored Cross-site Scripting vulnerability
Moderate
CVE-2018-17876
was published
for
web-feet/coastercms
(Composer)
May 14, 2022
Mediawiki tarball is missing .htaccess files
Moderate
CVE-2018-13258
was published
for
mediawiki/core
(Composer)
May 14, 2022
LibreNMS XSS Vulnerability
Moderate
CVE-2018-18478
was published
for
librenms/librenms
(Composer)
May 14, 2022
SabreDAV Directory Traversal vulnerability
Moderate
CVE-2013-1939
was published
for
sabre/dav
(Composer)
May 14, 2022
MantisBT allows XSS via the Manage Filter page
Moderate
CVE-2018-17782
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
MantisBT allows XSS via Edit Filter page
Moderate
CVE-2018-17783
was published
for
mantisbt/mantisbt
(Composer)
May 14, 2022
XSS in baserCMS before 4.1.4
Moderate
CVE-2018-18943
was published
for
baserproject/basercms
(Composer)
May 14, 2022
Showdoc Forced Browsing
Moderate
CVE-2018-19609
was published
for
showdoc/showdoc
(Composer)
May 14, 2022
Showdoc CSRF Vulnerability
Moderate
CVE-2018-19621
was published
for
showdoc/showdoc
(Composer)
May 14, 2022
XSS in PHP-Proxy-App through v3.0
Moderate
CVE-2018-19785
was published
for
athlon1600/php-proxy-app
(Composer)
May 14, 2022
Flarum Core Leaks PII
Moderate
CVE-2018-19133
was published
for
flarum/framework
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API