Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,780 advisories

Loading
Path Traversal in the Logs plugin for Craft CMS Moderate
CVE-2022-23409 was published for ether/logs (Composer) Feb 1, 2022
Cross-site Scripting in LiveHelperChat Moderate
CVE-2022-0395 was published for remdex/livehelperchat (Composer) Jan 29, 2022
Cross-site Scripting when rendering error messages in laminas-form Moderate
CVE-2022-23598 was published for laminas/laminas-form (Composer) Jan 28, 2022
Xerkus
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0387 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0370 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0374 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in livehelperchat Moderate
CVE-2022-0375 was published for remdex/livehelperchat (Composer) Jan 28, 2022
Cross-site Scripting in pimcore Moderate
CVE-2022-0348 was published for pimcore/pimcore (Composer) Jan 28, 2022
Improper Authentication in phpmyadmin Moderate
CVE-2022-23807 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
Cross-site Scripting in phpmyadmin Moderate
CVE-2022-23808 was published for phpmyadmin/phpmyadmin (Composer) Jan 28, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0379 was published for microweber/microweber (Composer) Jan 28, 2022
Cross-site Scripting in microweber Moderate
CVE-2022-0378 was published for microweber/microweber (Composer) Jan 28, 2022
Insufficient user authorization in Moodle Moderate
CVE-2022-0334 was published for moodle/moodle (Composer) Jan 28, 2022
Cross-site Scripting in Crater Invoice Moderate
CVE-2022-0372 was published for bytefury/crater (Composer) Jan 28, 2022
Cross-site Scripting in grav Moderate
CVE-2022-0268 was published for getgrav/grav (Composer) Jan 27, 2022
Cross-site Scripting Vulnerability in CodeIgniter4 Moderate
CVE-2022-21715 was published for codeigniter4/framework (Composer) Jan 27, 2022
kenjis
Cross-site Scripting in Pimcore Moderate
CVE-2022-0251 was published for pimcore/pimcore (Composer) Jan 27, 2022
Missing Authorization in Crater Invoice Moderate
CVE-2022-0203 was published for bytefury/crater (Composer) Jan 27, 2022
SQL Injection in showdoc Moderate
CVE-2022-0362 was published for showdoc/showdoc (Composer) Jan 27, 2022
Cross-site Scripting in pimcore Moderate
CVE-2022-0260 was published for pimcore/pimcore (Composer) Jan 26, 2022
Business Logic Errors in pimcore Moderate
CVE-2021-4146 was published for pimcore/pimcore (Composer) Jan 26, 2022
Improper Access Control in snipe-it Moderate
CVE-2022-0178 was published for snipe/snipe-it (Composer) Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat Moderate
CVE-2022-0231 was published for remdex/livehelperchat (Composer) Jan 26, 2022
Cross-Site Request Forgery (CSRF) in livehelperchat Moderate
CVE-2022-0226 was published for remdex/livehelperchat (Composer) Jan 26, 2022
Incorrect Default Permissions and Improper Access Control in snipe-it Moderate
CVE-2022-0179 was published for snipe/snipe-it (Composer) Jan 21, 2022
ProTip! Advisories are also available from the GraphQL API