GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Moodle reflected XSS
Moderate
CVE-2021-32478
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Moodle Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2021-32477
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Unrestricted Upload of File with Dangerous Type in Microweber
Moderate
CVE-2022-0921
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Unrestricted file upload leads to stored cross-site scripting in Microweber
Moderate
CVE-2022-0906
was published
for
microweber/microweber
(Composer)
Mar 11, 2022
Incorrect Authentication in shopware
Moderate
CVE-2022-24748
was published
for
shopware/core
(Composer)
Mar 10, 2022
HTTP caching is marking private HTTP headers as public in Shopware
Moderate
CVE-2022-24747
was published
for
shopware/core
(Composer)
Mar 10, 2022
HTML injection possibility in voucher code form in Shopware
Moderate
CVE-2022-24746
was published
for
shopware/core
(Composer)
Mar 10, 2022
Shopware guest session is shared between customers
Moderate
CVE-2022-24745
was published
for
shopware/platform
(Composer)
Mar 10, 2022
Cross-site Scripting in BookStack
Moderate
CVE-2022-0877
was published
for
ssddanbrown/bookstack
(Composer)
Mar 9, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0831
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
Cross-site Scripting in intelliants/subrion
Moderate
CVE-2020-18325
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0832
was published
for
pimcore/pimcore
(Composer)
Mar 5, 2022
Cross-site Scripting in Subrion CMS
Moderate
CVE-2020-18324
was published
for
intelliants/subrion
(Composer)
Mar 5, 2022
Cross-site Scripting in GeniXCMS
Moderate
CVE-2022-24563
was published
for
genix/cms
(Composer)
Mar 4, 2022
Cross site scripting in getgrav/grav
Moderate
CVE-2022-0743
was published
for
getgrav/grav
(Composer)
Mar 2, 2022
Cross-site Scripting in Cipi
Moderate
CVE-2022-26332
was published
for
andreapollastri/cipi
(Composer)
Mar 2, 2022
Improper regex in htaccess file
Moderate
CVE-2022-25769
was published
for
mautic/core
(Composer)
Mar 1, 2022
Cross-Site Request Forgery (CSRF) Protection Bypass Vulnerability in CodeIgniter4
Moderate
CVE-2022-24712
was published
for
codeigniter4/framework
(Composer)
Mar 1, 2022
Cross site scripting in LibreNMS
Moderate
CVE-2022-0772
was published
for
librenms/librenms
(Composer)
Feb 28, 2022
Exposure of Resource to Wrong Sphere in microweber
Moderate
CVE-2022-0762
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0763
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0723
was published
for
microweber/microweber
(Composer)
Feb 27, 2022
Logic error in dolibarr/dolibarr
Moderate
CVE-2022-0746
was published
for
dolibarr/dolibarr
(Composer)
Feb 26, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44566
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
Cross site scripting in francoisjacquet/rosariosis
Moderate
CVE-2021-44565
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 25, 2022
ProTip!
Advisories are also available from the
GraphQL API