GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            15 advisories
        Filter by severity
        
      
      
    
                    
                      XXE in PHPSpreadsheet due to encoding issue
                    
                      
  High
                    
                
                      
                        CVE-2018-19277
                      
                      was published
                        for
                        
                          phpoffice/phpexcel
                        
                        (Composer)
                      Nov 20, 2019 
                    
                  
                    
                      XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue
                    
                      
  High
                    
                
                      
                        CVE-2019-12331
                      
                      was published
                        for
                        
                          phpoffice/phpexcel
                        
                        (Composer)
                      Nov 20, 2019 
                    
                  
                    
                      Improper Access Control in moodle
                    
                      
  High
                    
                
                      
                        CVE-2020-25698
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Mar 29, 2021 
                    
                  
                    
                      Moodle vulnerable to PHP object injection attacks
                    
                      
  High
                    
                
                      
                        CVE-2014-3541
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle all messaging conversations could be viewed
                    
                      
  High
                    
                
                      
                        CVE-2019-10154
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      Moodle cross-site request forgery (CSRF) vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2016-2157
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle multiple cross-site request forgery (CSRF) vulnerabilities
                    
                      
  High
                    
                
                      
                        CVE-2015-5338
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Users could elevate their role when accessing the LTI tool on a provider site
                    
                      
  High
                    
                
                      
                        CVE-2019-3849
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle uses predictable password-recovery tokens
                    
                      
  High
                    
                
                      
                        CVE-2015-5267
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle XML import of ddwtos could lead to intentional remote code execution
                    
                      
  High
                    
                
                      
                        CVE-2018-14630
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Cross-site request forgery (CSRF) vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2016-3734
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle open redirect vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2015-3272
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Moodle Temporary Passwords are Brute Force-able
                    
                      
  High
                    
                
                      
                        CVE-2014-7845
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      RaspAP Command Injection vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2022-39987
                      
                      was published
                        for
                        
                          billz/raspap-webgui
                        
                        (Composer)
                      Aug 1, 2023 
                    
                  
                    
                      acf-to-rest-api plugin insecure direct object reference (IDOR) via permalink manipulation
                    
                      
  High
                    
                
                      
                        CVE-2020-13700
                      
                      was published
                        for
                        
                          airesvsg/acf-to-rest-api
                        
                        (Composer)
                      May 24, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API