GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,360
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
481 advisories
Filter by severity
baserCMS allows any file to be uploaded
Critical
CVE-2023-25655
was published
for
baserproject/basercms
(Composer)
Mar 23, 2023
baserCMS File Uploader Remote Code Execution (RCE) vulnerability
Critical
CVE-2023-25654
was published
for
baserproject/basercms
(Composer)
Mar 23, 2023
PHAR deserialization allowing remote code execution
Critical
CVE-2023-28115
was published
for
knplabs/knp-snappy
(Composer)
Mar 17, 2023
Access control issue in ezsystems/ezpublish-kernel
Critical
CVE-2022-48367
was published
for
ezsystems/ezpublish-kernel
(Composer)
Mar 12, 2023
Funadmin vulnerable to SQL injection
Critical
CVE-2023-24774
was published
for
funadmin/funadmin
(Composer)
Mar 10, 2023
Froxlor is vulnerable to authentication bypass
Critical
CVE-2023-1307
was published
for
froxlor/froxlor
(Composer)
Mar 10, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24777
was published
for
funadmin/funadmin
(Composer)
Mar 9, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24782
was published
for
funadmin/funadmin
(Composer)
Mar 8, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24773
was published
for
funadmin/funadmin
(Composer)
Mar 8, 2023
Easy!Appointments uses hard-coded credentials
Critical
CVE-2023-1269
was published
for
alextselegidis/easyappointments
(Composer)
Mar 8, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24780
was published
for
funadmin/funadmin
(Composer)
Mar 8, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24775
was published
for
funadmin/funadmin
(Composer)
Mar 7, 2023
SQL Injection in Funadmin
Critical
CVE-2023-24781
was published
for
funadmin/funadmin
(Composer)
Mar 7, 2023
Moodle SQL Injection vulnerability
Critical
CVE-2021-36393
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Moodle SQL Injection vulnerability
Critical
CVE-2021-36392
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
Remote code execution in Funadmin
Critical
CVE-2023-24776
was published
for
funadmin/funadmin
(Composer)
Mar 6, 2023
Cross-site Scripting in kimai/kimai
Critical
CVE-2020-19825
was published
for
kimai/kimai
(Composer)
Feb 16, 2023
Command Injection in thorsten/phpmyfaq
Critical
CVE-2023-0789
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
Code Injection in thorsten/phpmyfaq
Critical
CVE-2023-0788
was published
for
thorsten/phpmyfaq
(Composer)
Feb 12, 2023
SQL injection in webbuilders-group silverstripe-kapost-bridge
Critical
CVE-2015-10077
was published
for
webbuilders-group/silverstripe-kapost-bridge
(Composer)
Feb 10, 2023
Deserialization of Untrusted Data in thinkphp
Critical
CVE-2022-45982
was published
for
topthink/think
(Composer)
Feb 8, 2023
URI validation failure on SVG parsing. Bypass of CVE-2023-23924
Critical
CVE-2023-24813
was published
for
dompdf/dompdf
(Composer)
Feb 7, 2023
tinymighty WikiSEO is vulnerable to cross-site scripting via modifyHTML function
Critical
CVE-2015-10073
was published
for
tinymighty/wiki-seo
(Composer)
Feb 6, 2023
AVideo contains Command injection when embedding a video link
Critical
CVE-2023-25313
was published
for
wwbn/avideo
(Composer)
Feb 2, 2023
Dompdf vulnerable to URI validation failure on SVG parsing
Critical
CVE-2023-23924
was published
for
dompdf/dompdf
(Composer)
Feb 1, 2023
ProTip!
Advisories are also available from the
GraphQL API