GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,746
Erlang
35
GitHub Actions
29
Go
2,319
Maven
5,000+
npm
3,955
NuGet
712
pip
3,736
Pub
12
RubyGems
920
Rust
972
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,264 advisories
Filter by severity
Moodle has a SQL injection risk in course search module list filter
High
CVE-2025-26533
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
CodeIgniter4 DoS Vulnerability
High
CVE-2024-29904
was published
for
codeigniter4/framework
(Composer)
Mar 29, 2024
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
High
CVE-2025-46731
was published
for
craftcms/cms
(Composer)
May 5, 2025
Blind SQL Injection via GridFieldSortableHeader
High
CVE-2022-38148
was published
for
silverstripe/framework
(Composer)
Nov 22, 2022
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
High
CVE-2025-46349
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
High
CVE-2025-46347
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Drupal Two-factor Authentication (TFA) Vulnerable to Forceful Browsing
High
CVE-2025-31694
was published
for
drupal/tfa
(Composer)
Apr 1, 2025
Drupal OAuth2 Server Missing Authorization vulnerability
High
CVE-2025-31691
was published
for
drupal/oauth2_server
(Composer)
Apr 1, 2025
Drupal Open Social Missing Authorization vulnerability
High
CVE-2025-31686
was published
for
goalgorilla/open_social
(Composer)
Apr 1, 2025
Drupal Authenticator Login Missing Authorization vulnerability
High
CVE-2025-31681
was published
for
drupal/alogin
(Composer)
Apr 1, 2025
Account Takeover Through Password Reset Poisoning
High
CVE-2022-33012
was published
for
microweber/microweber
(Composer)
Nov 22, 2022
Browsershot does not validate URL protocols passed to Browsershot URL method
High
CVE-2022-41706
was published
for
spatie/browsershot
(Composer)
Nov 25, 2022
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
High
CVE-2025-3642
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
High
CVE-2025-3641
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Composer has a command injection via malicious git branch name
High
CVE-2024-35241
was published
for
composer/composer
(Composer)
Jun 10, 2024
Luracast Restler directory traversal vulnerability
High
CVE-2017-15363
was published
for
aoe/restler
(Composer)
May 13, 2022
MODX Revolution allows overwriting .htaccess
High
CVE-2017-9069
was published
for
modx/revolution
(Composer)
May 17, 2022
MODX Revolution Directory Traversal Vulnerability
High
CVE-2017-9067
was published
for
modx/revolution
(Composer)
May 17, 2022
MantisBT allows arbitrary password reset
High
CVE-2017-7615
was published
for
mantisbt/mantisbt
(Composer)
May 13, 2022
phpMyAdmin server-side request forgery (SSRF)
High
CVE-2016-6621
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
High
CVE-2022-47410
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
"Newsletter subscriber management" (fp_newsletter) TYPO3 extension leaks subscriber data
High
CVE-2022-47411
was published
for
fixpunkt/fp-newsletter
(Composer)
Dec 14, 2022
The Direct Mail (direct_mail) TYPO3 extension improperly discloses sensitive information
High
CVE-2013-7400
was published
for
directmailteam/direct-mail
(Composer)
May 13, 2022
phpMyAdmin SQL injection in user accounts page
High
CVE-2020-5504
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API