GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,744 advisories
Filter by severity
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
Low
CVE-2025-46350
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Cross-site Scripting in librenms/librenms
Moderate
CVE-2022-3561
was published
for
librenms/librenms
(Composer)
Nov 20, 2022
Cross-site Scripting in Backdrop CMS
Moderate
CVE-2022-42096
was published
for
backdrop/backdrop
(Composer)
Nov 21, 2022
YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download
Critical
CVE-2025-46348
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46549
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46550
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
ShowDoc unrestricted file upload vulnerability
Critical
CVE-2025-0520
was published
for
showdoc/showdoc
(Composer)
Apr 29, 2025
URL XSS vulnerability due to outdated jquery in CMS
Moderate
CVE-2022-38146
was published
for
silverstripe/admin
(Composer)
Nov 21, 2022
Blind SQL Injection via GridFieldSortableHeader
High
CVE-2022-38148
was published
for
silverstripe/framework
(Composer)
Nov 22, 2022
Moodle HTTP authorization header is preserved between "emulated redirects"
Moderate
CVE-2024-38275
was published
for
moodle/moodle
(Composer)
Jun 18, 2024
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
Moderate
CVE-2025-31674
was published
for
drupal/core
(Composer)
Apr 1, 2025
Magento Improper Authorization vulnerability
Moderate
CVE-2025-27188
was published
for
magento/community-edition
(Composer)
Apr 8, 2025
Froxlor vulnerable to Code Injection
Moderate
CVE-2022-3721
was published
for
froxlor/froxlor
(Composer)
Nov 4, 2022
Grokability Snipe-IT has incorrect authorization for accessing asset information
Moderate
CVE-2025-47226
was published
for
snipe/snipe-it
(Composer)
May 2, 2025
league/commonmark contains a XSS vulnerability in Attributes extension
Moderate
CVE-2025-46734
was published
for
league/commonmark
(Composer)
May 5, 2025
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
High
CVE-2025-46731
was published
for
craftcms/cms
(Composer)
May 5, 2025
Showdoc Unauthenticated Access
Moderate
CVE-2018-19620
was published
for
showdoc/showdoc
(Composer)
May 13, 2022
CodeIgniter4 DoS Vulnerability
High
CVE-2024-29904
was published
for
codeigniter4/framework
(Composer)
Mar 29, 2024
Moodle has reflected Cross-site Scripting risk in policy tool
Moderate
CVE-2025-3643
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a SQL injection risk in course search module list filter
High
CVE-2025-26533
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2013-4522
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Incorrect Authorization vulnerability
High
CVE-2020-14321
was published
for
moodle/moodle
(Composer)
Aug 17, 2022
Koillection Cross Site Scripting vulnerability
Moderate
CVE-2025-29746
was published
for
koillection/koillection
(Composer)
May 7, 2025
Easy!Appointments Denial of Service (DoS)
Moderate
CVE-2025-29448
was published
for
alextselegidis/easyappointments
(Composer)
May 7, 2025
ProTip!
Advisories are also available from the
GraphQL API