Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,781 advisories

Loading
Drupal AI Vulnerable to OS Command Injection Moderate
CVE-2025-31693 was published for drupal/ai (Composer) Apr 1, 2025
Snipe-IT allows attackers to check whether a user account exists Moderate
CVE-2022-44381 was published for snipe/snipe-it (Composer) Dec 25, 2022
Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets Moderate
CVE-2022-44380 was published for snipe/snipe-it (Composer) Dec 25, 2022
Bootstrap Cross-Site Scripting (XSS) vulnerability Moderate
CVE-2024-6531 was published for bootstrap (RubyGems) Jul 11, 2024
alexeyNeklesa-idt metametadata
Typo3 Host Header Spoofing Vulnerability Moderate
CVE-2014-3941 was published for typo3/cms (Composer) May 14, 2022
Typo3 Information Disclosure Moderate
CVE-2014-3946 was published for typo3/cms (Composer) May 17, 2022
phpMyAdmin vulnerable to Cross-site Scripting Moderate
CVE-2016-5733 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting Moderate
CVE-2016-5705 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
phpMyAdmin vulnerable to Cross-site Scripting Moderate
CVE-2016-5701 was published for phpmyadmin/phpmyadmin (Composer) May 14, 2022
TYPO3 Cross-site Scripting vulnerability Moderate
CVE-2015-8759 was published for typo3/cms (Composer) May 17, 2022
TYPO3 CMS indexed search Cross-site Scripting vulnerability Moderate
CVE-2015-8756 was published for typo3/cms (Composer) May 17, 2022
TYPO3 allows remote attackers to embed Flash videos from external domain Moderate
CVE-2015-8760 was published for typo3/cms (Composer) May 17, 2022
fal_sftp extension for TYPO3 uses weak permissions for sFTP driver files and folders Moderate
CVE-2014-8327 was published for co-stack/fal_sftp (Composer) May 17, 2022
TYPO3 powermail extension allows remote attackers to bypass CAPTCHA protection mechanism Moderate
CVE-2014-6288 was published for in2code/powermail (Composer) May 17, 2022
TYPO3 femanager extension allows remote frontend users to modify or delete records of other frontend users Moderate
CVE-2014-6292 was published for in2code/femanager (Composer) May 13, 2022
GeSHi vulnerable to Cross-site Scripting Moderate
CVE-2012-3522 was published for geshi/geshi (Composer) May 17, 2022
YUI Cross-site Scripting (XSS) vulnerability Moderate
CVE-2013-4942 was published for moodle/moodle (Composer) May 13, 2022
YUI Cross-site Scripting (XSS) vulnerability Moderate
CVE-2013-4941 was published for moodle/moodle (Composer) May 13, 2022
YUI Cross-site Scripting (XSS) vulnerability Moderate
CVE-2013-4940 was published for moodle/moodle (Composer) May 13, 2022
Front End User Registration (sr_feuser_register) extension for TYPO3 allows remote attackers to obtain user names, passwords Moderate
CVE-2012-5890 was published for sjbr/sr-feuser-register (Composer) May 17, 2022
TYPO3 allows remote authenticated backend users to unserialize arbitrary objects Moderate
CVE-2012-3527 was published for typo3/cms (Composer) May 17, 2022
TYPO3 allows remote attackers to obtain the database name via a direct request Moderate
CVE-2012-1607 was published for typo3/cms (Composer) May 17, 2022
Moodle does not properly restrict comment capabilities Moderate
CVE-2011-4297 was published for moodle/moodle (Composer) May 13, 2022
Moodle vulnerable to Cross-site Scripting Moderate
CVE-2011-4286 was published for moodle/moodle (Composer) May 13, 2022
Moodle does not use the forceloginforprofiles setting for course-profiles access control Moderate
CVE-2011-4279 was published for moodle/moodle (Composer) May 13, 2022
ProTip! Advisories are also available from the GraphQL API