GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,179
Erlang
31
GitHub Actions
19
Go
1,982
Maven
5,000+
npm
3,701
NuGet
656
pip
3,323
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,399 advisories
Filter by severity
Symfony allows changing the environment through a query
Moderate
CVE-2024-50340
was published
for
symfony/runtime
(Composer)
Nov 6, 2024
UnoPim Cross-site Scripting vulnerability
Moderate
CVE-2024-50637
was published
for
unopim/unopim
(Composer)
Nov 6, 2024
Potential XSS vulnerability in jQuery
Moderate
CVE-2020-11022
was published
for
jquery
(RubyGems)
Apr 29, 2020
XSS in jQuery as used in Drupal, Backdrop CMS, and other products
Moderate
CVE-2019-11358
was published
for
django
(RubyGems)
Apr 26, 2019
Moodle BigBlueButton web service leaks meeting joining information
Moderate
CVE-2024-38273
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
Cross-site Scripting in Moodle Chat
Moderate
CVE-2024-28593
was published
for
moodle/moodle
(Composer)
Mar 22, 2024
mdanter/ecc affected by timing vulnerability in cryptographic side-channels
Moderate
CVE-2024-33851
was published
for
mdanter/ecc
(Composer)
Apr 28, 2024
Symfony potential Cross-site Scripting in WebhookController
Moderate
CVE-2023-46735
was published
for
symfony/symfony
(Composer)
Nov 12, 2023
Cross-site scripting vulnerability in includes/actions/InfoAction.php
Moderate
CVE-2014-2853
was published
for
mediawiki/core
(Composer)
May 17, 2022
img_auth.php may leak private extension images into the public cache
Moderate
CVE-2020-15005
was published
for
mediawiki/core
(Composer)
May 24, 2022
Enhavo Cross-site Scripting vulnerability
Moderate
CVE-2024-25876
was published
for
enhavo/enhavo-app
(Composer)
Feb 22, 2024
phpBB's Smiley Pack acp_icons.php main pack vulnerable to cross site scripting
Moderate
CVE-2023-5917
was published
for
phpbb/phpbb
(Composer)
Nov 2, 2023
HTML Purifier allows remote attackers to obtain sensitive information
Moderate
CVE-2011-3744
was published
for
ezyang/htmlpurifier
(Composer)
May 17, 2022
HTML Purifier Cross-site Scripting vulnerability
Moderate
CVE-2007-3498
was published
for
ezyang/htmlpurifier
(Composer)
May 1, 2022
TYPO3 CMS vulnerable to Sensitive Information Disclosure via YAML Placeholder Expressions in Site Configuration
Moderate
CVE-2022-23504
was published
for
typo3/cms
(Composer)
Dec 13, 2022
Drupal Full Path Disclosure
Moderate
CVE-2024-45440
was published
for
drupal/core
(Composer)
Aug 29, 2024
Fluid Components TYPO3 extension vulnerable to Cross-Site Scripting
Moderate
CVE-2023-28604
was published
for
sitegeist/fluid-components
(Composer)
Mar 27, 2023
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Edit Email Form Settings Feature
Moderate
CVE-2024-46998
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts Feature
Moderate
CVE-2024-46996
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
Cross site scripting in ameos_tarteaucitron
Moderate
CVE-2022-33155
was published
for
ameos/ameos_tarteaucitron
(Composer)
Jul 13, 2022
Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled
Moderate
CVE-2024-49762
was published
for
pterodactyl/panel
(Composer)
Oct 24, 2024
ai-admin-graphql has a Denial of service vulnerability in SaaS and marketplace setups
Moderate
CVE-2024-47173
was published
for
aimeos/ai-admin-graphql
(Composer)
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in HTTP 400 Bad Request
Moderate
CVE-2024-46995
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
baserCMS has a Cross-site Scripting (XSS) Vulnerability in Blog posts and Contents list Feature
Moderate
CVE-2024-46994
was published
for
baserproject/basercms
(Composer)
Oct 24, 2024
derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module
Moderate
CVE-2024-24751
was published
for
derhansen/sf_event_mgt
(Composer)
Feb 13, 2024
ProTip!
Advisories are also available from the
GraphQL API