Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,781 advisories

Loading
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-4015 was published for grumpydictator/firefly-iii (Composer) Dec 6, 2021
Cross-site Scripting in pegasus/google-for-jobs Moderate
CVE-2021-43561 was published for pegasus/google-for-jobs (Composer) Nov 15, 2021
twill is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3932 was published for area17/twill (Composer) Nov 15, 2021
firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3921 was published for grumpydictator/firefly-iii (Composer) Nov 15, 2021
Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content. Moderate
CVE-2021-43617 was published for laravel/framework (Composer) Nov 16, 2021 withdrawn
Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys Moderate
CVE-2021-41273 was published for pterodactyl/panel (Composer) Nov 18, 2021
Haxatron
elgg is vulnerable to Authorization Bypass Through User-Controlled Key Moderate
CVE-2021-3964 was published for elgg/elgg (Composer) Dec 3, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF) Moderate
CVE-2021-3775 was published for showdoc/showdoc (Composer) Nov 15, 2021
Authenticated Stored XSS in shopware/shopware Moderate
CVE-2021-41188 was published for shopware/shopware (Composer) Oct 27, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3976 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3957 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Cross-site Scripting in kimai2 Moderate
CVE-2021-3963 was published for kevinpapst/kimai2 (Composer) Nov 23, 2021
Exposure of sensitive information in concrete5/core Moderate
CVE-2021-22967 was published for concrete5/core (Composer) Nov 23, 2021
Cross-site scripting (XSS) from writer field content in the site frontend Moderate
CVE-2021-41252 was published for getkirby/cms (Composer) Nov 16, 2021
azrultech
snipe-it is vulnerable to Cross-site Scripting Moderate
CVE-2021-4018 was published for snipe/snipe-it (Composer) Dec 3, 2021
Cross-site Scripting in LibreNMS Moderate
CVE-2021-44279 was published for librenms/librenms (Composer) Dec 3, 2021
showdoc is vulnerable to URL Redirection to Untrusted Site Moderate
CVE-2021-3989 was published for showdoc/showdoc (Composer) Dec 3, 2021
Cross-site Scripting in yourls Moderate
CVE-2021-3785 was published for yourls/yourls (Composer) Sep 20, 2021
Exposed phpinfo() leadked via documentation files Moderate
CVE-2021-37704 was published for phpfastcache/phpfastcache (Composer) Aug 30, 2021
Geolim4
Cross-Site Scripting in grav Moderate
CVE-2021-3904 was published for getgrav/grav (Composer) Nov 1, 2021
Cross-Site Request Forgery in firefly-iii Moderate
CVE-2021-3900 was published for grumpydictator/firefly-iii (Composer) Oct 28, 2021
Improper Restriction of Rendered UI Layers or Frames in yourls Moderate
CVE-2021-3734 was published for yourls/yourls (Composer) Aug 30, 2021
Cross-site Scripting in snipe-it Moderate
CVE-2021-3863 was published for snipe/snipe-it (Composer) Oct 21, 2021
Manipulation of product reviews via API Moderate
CVE-2021-37707 was published for shopware/core (Composer) Aug 30, 2021
Exposure of Sensitive Information to an Unauthorized Actor in Moodle Moderate
CVE-2020-25703 was published for moodle/moodle (Composer) Oct 21, 2021
ProTip! Advisories are also available from the GraphQL API