GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,781
Erlang
36
GitHub Actions
29
Go
2,345
Maven
5,000+
npm
3,976
NuGet
719
pip
3,772
Pub
12
RubyGems
923
Rust
980
Swift
38
Unreviewed advisories
All unreviewed
5,000+
83 advisories
Filter by severity
phpMyAdmin Improper Input Validation
Moderate
CVE-2016-2562
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 OpenID extension Open redirect vulnerability
Moderate
CVE-2013-7079
was published
for
friendsoftypo3/openid
(Composer)
May 17, 2022
XMPP Clients User Impersonation Vulnerability in Movim Moxl
Moderate
CVE-2017-5605
was published
for
movim/moxl
(Composer)
May 17, 2022
Laravel does not properly constrain the host portion of a password-reset URL
Moderate
CVE-2017-9303
was published
for
illuminate/auth
(Composer)
May 17, 2022
phpMyAdmin DoS Vulnerability
Moderate
CVE-2016-6623
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin Denial of Service (DoS)
Moderate
CVE-2016-9860
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
phpMyAdmin allows remote attackers to obtain installation path via direct request for nonexistent file
Moderate
CVE-2011-0986
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 Path Traversal vulnerability
Moderate
CVE-2010-5099
was published
for
typo3/cms
(Composer)
May 17, 2022
GeniXCMS denial of service (account blockage)
Moderate
CVE-2017-14231
was published
for
genix/cms
(Composer)
May 17, 2022
Typo3 Host Header Spoofing Vulnerability
Moderate
CVE-2014-3941
was published
for
typo3/cms
(Composer)
May 14, 2022
Symfony SSRF Vulnerability via Form Component
Moderate
CVE-2017-16790
was published
for
symfony/form
(Composer)
May 14, 2022
SabreDAV Directory Traversal vulnerability
Moderate
CVE-2013-1939
was published
for
sabre/dav
(Composer)
May 14, 2022
Drupal file REST resource does not properly validate
Moderate
CVE-2017-6921
was published
for
drupal/core
(Composer)
May 13, 2022
Piwik (now Matomo) Reveals Sensitive Information by Accepting Input from `POST` Requests
Moderate
CVE-2013-2633
was published
for
matomo/matomo
(Composer)
May 13, 2022
Moodle allows remote authenticated users to cause a denial of service (invalid database records)
Moderate
CVE-2011-4291
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
Moderate
CVE-2013-2083
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Arbitrary File Read via Backup Functionality
Moderate
CVE-2012-6099
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to trigger the generation of arbitrary messages
Moderate
CVE-2014-9060
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Incorrect sanitation of attributes in forums
Moderate
CVE-2017-2576
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly validate module instance id
Moderate
CVE-2006-4936
was published
for
moodle/moodle
(Composer)
May 1, 2022
Typo3 Improper Access Control
Moderate
CVE-2011-4904
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Typo3 Arbitrary File Delete
Moderate
CVE-2011-4902
was published
for
typo3/cms
(Composer)
Apr 22, 2022
TYPO3 is vulnerable to Spam Abuse in the native form content element
Moderate
CVE-2010-3667
was published
for
typo3/cms-frontend
(Composer)
Apr 21, 2022
FormField with square brackets in field name skips validation
Moderate
CVE-2020-26138
was published
for
silverstripe/framework
(Composer)
Mar 26, 2022
Improper Input Validation in guzzlehttp/psr7
Moderate
CVE-2022-24775
was published
for
guzzlehttp/psr7
(Composer)
Mar 25, 2022
ProTip!
Advisories are also available from the
GraphQL API