GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,866
Erlang
36
GitHub Actions
36
Go
2,491
Maven
5,000+
npm
4,110
NuGet
735
pip
3,933
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
4,867 advisories
Filter by severity
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0964
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0966
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Stored Cross-site Scripting in grav
High
CVE-2022-0970
was published
for
getgrav/grav
(Composer)
Mar 16, 2022
DQL injection through sorting parameters blocked
Critical
CVE-2022-24752
was published
for
sylius/grid-bundle
(Composer)
Mar 15, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0894
was published
for
pimcore/pimcore
(Composer)
Mar 16, 2022
Unrestricted XML files leading to cross-site scripting in Microweber
Moderate
CVE-2022-0963
was published
for
microweber/microweber
(Composer)
Mar 16, 2022
Stored Cross-site Scripting in Microweber
Moderate
CVE-2022-0954
was published
for
microweber/microweber
(Composer)
Mar 16, 2022
Cross-site Scripting in Zenario CMS
Moderate
CVE-2021-41952
was published
for
tribalsystems/zenario
(Composer)
Mar 15, 2022
Unrestricted Upload of File with Dangerous Type in Zenario CMS
Critical
CVE-2021-42171
was published
for
tribalsystems/zenario
(Composer)
Mar 15, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0937
was published
for
showdoc/showdoc
(Composer)
Mar 15, 2022
Stored Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0945
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0950
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0942
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
File Upload Restriction Bypass leading to Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0951
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0957
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0956
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0965
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Denial of service in microweber
High
CVE-2022-0961
was published
for
microweber/microweber
(Composer)
Mar 16, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0705
was published
for
pimcore/pimcore
(Composer)
Mar 17, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0704
was published
for
pimcore/pimcore
(Composer)
Mar 17, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0911
was published
for
pimcore/pimcore
(Composer)
Mar 17, 2022
Arbitrary File Deletion vulnerability in OctoberCMS
Moderate
CVE-2020-5296
was published
for
october/cms
(Composer)
Jun 3, 2020
Local File read vulnerability in OctoberCMS
Moderate
CVE-2020-5295
was published
for
october/cms
(Composer)
Jun 3, 2020
Upload whitelisted files to any directory in OctoberCMS
Low
CVE-2020-5297
was published
for
october/cms
(Composer)
Jun 3, 2020
Pterodactyl Panel vulnerable to authentication bypass due to improper user-provided security token verification
High
CVE-2021-41129
was published
for
pterodactyl/panel
(Composer)
Oct 4, 2021
ProTip!
Advisories are also available from the
GraphQL API