GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,781 advisories
Filter by severity
Cross-Site Request Forgery in Drupal core
Moderate
CVE-2020-13674
was published
for
drupal/core
(Composer)
Feb 12, 2022
Drupal core Cross-site Scripting (XSS) vulnerability
Moderate
CVE-2020-13672
was published
for
drupal/core
(Composer)
Feb 12, 2022
Drupal core Cross-site Scripting (XSS) vulnerability in ckeditor
Moderate
CVE-2020-13669
was published
for
drupal/core
(Composer)
Feb 12, 2022
Incorrect Authorization in Drupal core
Moderate
CVE-2020-13676
was published
for
drupal/core
(Composer)
Feb 12, 2022
Path Traversal in S-Cart
Moderate
CVE-2021-44111
was published
for
s-cart/s-cart
(Composer)
Feb 12, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0558
was published
for
microweber/microweber
(Composer)
Feb 11, 2022
Cross-site scripting in forkcms
Moderate
CVE-2020-23263
was published
for
forkcms/forkcms
(Composer)
Feb 10, 2022
Unrestricted Uploads in Concrete5
Moderate
CVE-2020-14961
was published
for
concrete5/concrete5
(Composer)
Feb 10, 2022
Cross-Site Request Forgery in CakePHP
Moderate
CVE-2020-15400
was published
for
cakephp/cakephp
(Composer)
Feb 10, 2022
Cross-site Scripting in RosarioSIS
Moderate
CVE-2020-15721
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 10, 2022
Cross-site Scripting in Contao
Moderate
CVE-2018-10125
was published
for
contao/contao
(Composer)
Feb 10, 2022
Studio 42 elFinder allows stored XSS
Moderate
CVE-2021-45919
was published
for
studio-42/elfinder
(Composer)
Feb 10, 2022
Cross-site Scripting in Beanstalk console
Moderate
CVE-2022-0539
was published
for
ptrofimov/beanstalk_console
(Composer)
Feb 10, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0506
was published
for
microweber/microweber
(Composer)
Feb 9, 2022
Generation of Error Message Containing Sensitive Information in microweber
Moderate
CVE-2022-0504
was published
for
microweber/microweber
(Composer)
Feb 9, 2022
Cross-Site Request Forgery in microweber
Moderate
CVE-2022-0505
was published
for
microweber/microweber
(Composer)
Feb 9, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0509
was published
for
pimcore/pimcore
(Composer)
Feb 9, 2022
Cross-site Scripting pimcore
Moderate
CVE-2022-0510
was published
for
pimcore/pimcore
(Composer)
Feb 9, 2022
Cross-site Scripting in LiveHelperChat
Moderate
CVE-2022-0502
was published
for
remdex/livehelperchat
(Composer)
Feb 7, 2022
Unrestricted Upload of File with Dangerous Type in jsdecena/laracom
Moderate
CVE-2022-0472
was published
for
jsdecena/laracom
(Composer)
Feb 6, 2022
Business Logic Errors in SilverStripe Framework
Moderate
CVE-2022-0227
was published
for
silverstripe/framework
(Composer)
Feb 6, 2022
Cross-site Scripting in Beanstalk console
Moderate
CVE-2022-0501
was published
for
ptrofimov/beanstalk_console
(Composer)
Feb 6, 2022
RosarioSIS XSS Vulnerability
Moderate
CVE-2021-45416
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 2, 2022
Dolibarr vulnerable to Improper Validation of Specified Quantity in Input
Moderate
CVE-2022-0414
was published
for
dolibarr/dolibarr
(Composer)
Feb 1, 2022
Cross-site Scripting in LiveHelperChat
Moderate
CVE-2022-0394
was published
for
remdex/livehelperchat
(Composer)
Feb 1, 2022
ProTip!
Advisories are also available from the
GraphQL API