GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
63 advisories
Filter by severity
Magento affected by a server-side denial-of-service using a GraphQL field
High
CVE-2021-36044
was published
for
magento/community-edition
(Composer)
May 24, 2022
EC-CUBE Improper input validation vulnerability
High
CVE-2020-5680
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
Moodle vulnerable to RCE
High
CVE-2020-10738
was published
for
moodle/moodle
(Composer)
May 24, 2022
Froxlor arbitrary code execution via the database configuration options
High
CVE-2020-10235
was published
for
froxlor/froxlor
(Composer)
May 24, 2022
Magento arbitrary PHP code execution via the productData parameter
High
CVE-2015-6497
was published
for
magento/core
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-7885
was published
for
magento/community-edition
(Composer)
May 24, 2022
CakePHP allows remote attackers to modify internal Cake cache and execute arbitrary code
High
CVE-2010-4335
was published
for
cakephp/cakephp
(Composer)
May 17, 2022
Drupal has open redirect vulnerability in the Overlay module
High
CVE-2013-6389
was published
for
drupal/drupal
(Composer)
May 17, 2022
TYPO3 doesn't properly check file extensions
High
CVE-2013-4250
was published
for
typo3/cms
(Composer)
May 17, 2022
Typo3 Vulnerable to Cache Poisoning
High
CVE-2014-9509
was published
for
typo3/cms
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to spoof content via the url parameter
High
CVE-2015-7873
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2016-9863
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Cookie attribute injection attack
High
CVE-2017-1000016
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
CodeIgniter HTTP Header Injection
High
CVE-2017-1000247
was published
for
codeigniter4/framework
(Composer)
May 17, 2022
Moodle Portfolio script allows instantiation of class chosen by user
High
CVE-2018-1137
was published
for
moodle/moodle
(Composer)
May 14, 2022
Symfony Host Header Injection
High
CVE-2018-14774
was published
for
symfony/symfony
(Composer)
May 14, 2022
CakePHP allows remote attackers to spoof their IP
High
CVE-2016-4793
was published
for
cakephp/cakephp
(Composer)
May 14, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000014
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin DoS Vulnerability
High
CVE-2017-1000018
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
SimpleSAMLphp InfoCard module Incorrect signature verification
High
CVE-2017-12874
was published
for
simplesamlphp/simplesamlphp-module-infocard
(Composer)
May 14, 2022
SimpleSAMLphp Authentication context bypass in the multiauth module
High
CVE-2017-12869
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
Moodle XSS Vulnerability
High
CVE-2018-10891
was published
for
moodle/moodle
(Composer)
May 13, 2022
Symfony collectionCascaded and collectionCascadedDeeply fields security bypass
High
CVE-2013-4751
was published
for
symfony/symfony
(Composer)
May 5, 2022
phpMyAdmin HTTP Response Splitting Vulnerability
High
CVE-2009-1149
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API