GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,311
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
964
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,263 advisories
Filter by severity
Deserialization of Untrusted Data in Codeigniter4
High
CVE-2022-21647
was published
for
codeigniter4/framework
(Composer)
Jan 6, 2022
Injection in UserFrosting
High
CVE-2021-25994
was published
for
userfrosting/userfrosting
(Composer)
Jan 6, 2022
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4131
was published
for
remdex/livehelperchat
(Composer)
Jan 5, 2022
snipe-it is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4130
was published
for
snipe/snipe-it
(Composer)
Jan 5, 2022
YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number
High
CVE-2021-4111
was published
for
yetiforce/yetiforce-crm
(Composer)
Dec 16, 2021
Privilege escalation in the Sulu Admin panel
High
CVE-2021-43835
was published
for
sulu/sulu
(Composer)
Dec 15, 2021
PHP file inclusion in the Sulu admin panel
High
CVE-2021-43836
was published
for
sulu/sulu
(Composer)
Dec 15, 2021
SQL injection in jackalope/jackalope-doctrine-dbal
High
CVE-2021-43822
was published
for
jackalope/jackalope-doctrine-dbal
(Composer)
Dec 14, 2021
Server-Side Request Forgery in snipe/snipe-it
High
CVE-2021-4075
was published
for
snipe/snipe-it
(Composer)
Dec 10, 2021
SQL injection in prestashop/prestashop
High
CVE-2021-43789
was published
for
prestashop/prestashop
(Composer)
Dec 7, 2021
kimai2 is vulnerable to Cross-site Scripting
High
CVE-2021-3985
was published
for
kevinpapst/kimai2
(Composer)
Dec 3, 2021
showdoc is vulnerable to Cross-Site Request Forgery (CSRF)
High
CVE-2021-4017
was published
for
showdoc/showdoc
(Composer)
Dec 3, 2021
Potential Zip Slip Vulnerability in baserCMS
High
CVE-2021-41279
was published
for
baserproject/basercms
(Composer)
Dec 1, 2021
Improper Privilege Management in Concrete CMS
High
CVE-2021-22966
was published
for
concrete5/core
(Composer)
Nov 23, 2021
Cross-site Scripting in snipe/snipe-it
High
CVE-2021-3961
was published
for
snipe/snipe-it
(Composer)
Nov 23, 2021
Improper file handling in concrete5/core
High
CVE-2021-22968
was published
for
concrete5/core
(Composer)
Nov 23, 2021
HTML comments vulnerability allowing to execute JavaScript code
High
CVE-2021-41165
was published
for
ckeditor/ckeditor
(Composer)
Nov 17, 2021
bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type
High
CVE-2021-3915
was published
for
ssddanbrown/bookstack
(Composer)
Nov 15, 2021
Unrestricted access to predictable file paths in hov/jobfair
High
CVE-2021-43564
was published
for
hov/jobfair
(Composer)
Nov 15, 2021
Insecure Inherited Permissions in neoan3-apps/template
High
CVE-2021-41170
was published
for
neoan3-apps/template
(Composer)
Nov 10, 2021
Unrestricted Uploads in Concrete5
High
CVE-2020-11476
was published
for
concrete5/concrete5
(Composer)
Nov 3, 2021
CSV Injection Vulnerability
High
CVE-2021-41824
was published
for
craftcms/cms
(Composer)
Oct 18, 2021
Server-Side Request Forgery vulnerability in concrete5
High
CVE-2021-22958
was published
for
concrete5/concrete5
(Composer)
Oct 12, 2021
ProTip!
Advisories are also available from the
GraphQL API