GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,868
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,117
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
2,780 advisories
Filter by severity
Path Traversal in the Logs plugin for Craft CMS
Moderate
CVE-2022-23409
was published
for
ether/logs
(Composer)
Feb 1, 2022
Cross-site Scripting in LiveHelperChat
Moderate
CVE-2022-0395
was published
for
remdex/livehelperchat
(Composer)
Jan 29, 2022
Cross-site Scripting when rendering error messages in laminas-form
Moderate
CVE-2022-23598
was published
for
laminas/laminas-form
(Composer)
Jan 28, 2022
Cross-site Scripting in livehelperchat
Moderate
CVE-2022-0387
was published
for
remdex/livehelperchat
(Composer)
Jan 28, 2022
Cross-site Scripting in livehelperchat
Moderate
CVE-2022-0370
was published
for
remdex/livehelperchat
(Composer)
Jan 28, 2022
Cross-site Scripting in livehelperchat
Moderate
CVE-2022-0374
was published
for
remdex/livehelperchat
(Composer)
Jan 28, 2022
Cross-site Scripting in livehelperchat
Moderate
CVE-2022-0375
was published
for
remdex/livehelperchat
(Composer)
Jan 28, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0348
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2022
Improper Authentication in phpmyadmin
Moderate
CVE-2022-23807
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 28, 2022
Cross-site Scripting in phpmyadmin
Moderate
CVE-2022-23808
was published
for
phpmyadmin/phpmyadmin
(Composer)
Jan 28, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0379
was published
for
microweber/microweber
(Composer)
Jan 28, 2022
Cross-site Scripting in microweber
Moderate
CVE-2022-0378
was published
for
microweber/microweber
(Composer)
Jan 28, 2022
Insufficient user authorization in Moodle
Moderate
CVE-2022-0334
was published
for
moodle/moodle
(Composer)
Jan 28, 2022
Cross-site Scripting in Crater Invoice
Moderate
CVE-2022-0372
was published
for
bytefury/crater
(Composer)
Jan 28, 2022
Cross-site Scripting in grav
Moderate
CVE-2022-0268
was published
for
getgrav/grav
(Composer)
Jan 27, 2022
Cross-site Scripting Vulnerability in CodeIgniter4
Moderate
CVE-2022-21715
was published
for
codeigniter4/framework
(Composer)
Jan 27, 2022
Cross-site Scripting in Pimcore
Moderate
CVE-2022-0251
was published
for
pimcore/pimcore
(Composer)
Jan 27, 2022
Missing Authorization in Crater Invoice
Moderate
CVE-2022-0203
was published
for
bytefury/crater
(Composer)
Jan 27, 2022
SQL Injection in showdoc
Moderate
CVE-2022-0362
was published
for
showdoc/showdoc
(Composer)
Jan 27, 2022
Cross-site Scripting in pimcore
Moderate
CVE-2022-0260
was published
for
pimcore/pimcore
(Composer)
Jan 26, 2022
Business Logic Errors in pimcore
Moderate
CVE-2021-4146
was published
for
pimcore/pimcore
(Composer)
Jan 26, 2022
Improper Access Control in snipe-it
Moderate
CVE-2022-0178
was published
for
snipe/snipe-it
(Composer)
Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0231
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat
Moderate
CVE-2022-0226
was published
for
remdex/livehelperchat
(Composer)
Jan 26, 2022
Incorrect Default Permissions and Improper Access Control in snipe-it
Moderate
CVE-2022-0179
was published
for
snipe/snipe-it
(Composer)
Jan 21, 2022
ProTip!
Advisories are also available from the
GraphQL API