GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
63 advisories
Filter by severity
Magento affected by a server-side denial-of-service using a GraphQL field
High
CVE-2021-36044
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento vulnerable to file upload attack
High
CVE-2021-36041
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento affected by remote code execution via a file upload
High
CVE-2021-36034
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento is affected by an improper input validation vulnerability
High
CVE-2021-36032
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento allows attackers to alter the price of items
High
CVE-2021-36030
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento vulnerable to denial of service
High
CVE-2025-49554
was published
for
magento/community-edition
(Composer)
Aug 12, 2025
Browsershot does not validate URL protocols passed to Browsershot URL method
High
CVE-2022-41706
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
phpMyAdmin allows remote attackers to spoof content via the url parameter
High
CVE-2015-7873
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 doesn't properly check file extensions
High
CVE-2013-4250
was published
for
typo3/cms
(Composer)
May 17, 2022
Shopware allows Denial Of Service via password length
High
CVE-2025-30151
was published
for
shopware/core
(Composer)
Apr 8, 2025
Magento Open Source allows Improper Input Validation
High
CVE-2024-20758
was published
for
magento/community-edition
(Composer)
Apr 10, 2024
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
Arbitrary File Creation in opencart
High
CVE-2024-21519
was published
for
opencart/opencart
(Composer)
Jun 22, 2024
Drupal has open redirect vulnerability in the Overlay module
High
CVE-2013-6389
was published
for
drupal/drupal
(Composer)
May 17, 2022
Livewire Remote Code Execution on File Uploads
High
CVE-2024-47823
was published
for
livewire/livewire
(Composer)
Oct 8, 2024
Moodle ReCAPTCHA can be bypassed on the login page
High
CVE-2024-34009
was published
for
moodle/moodle
(Composer)
May 31, 2024
Moodle Improper Input Validation
High
CVE-2024-33999
was published
for
moodle/moodle
(Composer)
May 31, 2024
TYPO3 Arbitrary Shell Execution in Swiftmailer library
High
GHSA-45xg-4w5x-j429
was published
for
typo3/cms
(Composer)
May 30, 2024
silverstripe/framework has possible denial of service attack vector when flushing
High
GHSA-cwgq-83w5-8jfq
was published
for
silverstripe/framework
(Composer)
May 28, 2024
SimpleSAMLphp Authentication context bypass in the multiauth module
High
CVE-2017-12869
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
Froxlor arbitrary code execution via the database configuration options
High
CVE-2020-10235
was published
for
froxlor/froxlor
(Composer)
May 24, 2022
SimpleSAMLphp InfoCard module Incorrect signature verification
High
CVE-2017-12874
was published
for
simplesamlphp/simplesamlphp-module-infocard
(Composer)
May 14, 2022
EC-CUBE Improper input validation vulnerability
High
CVE-2020-5680
was published
for
ec-cube/ec-cube
(Composer)
May 24, 2022
CodeIgniter HTTP Header Injection
High
CVE-2017-1000247
was published
for
codeigniter4/framework
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API