GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            74 advisories
        Filter by severity
        
      
      
    
                    
                      Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-26255
                      
                      was published
                        for
                        
                          getkirby/cms
                        
                        (Composer)
                      Dec 8, 2020 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in Microweber
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0921
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Mar 12, 2022 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in microweber
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0912
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Mar 12, 2022 
                    
                  
                    
                      Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-24749
                      
                      was published
                        for
                        
                          Sylius/Sylius
                        
                        (Composer)
                      Mar 14, 2022 
                    
                  
                    
                      Cross-site Scripting in ShowDoc
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0950
                      
                      was published
                        for
                        
                          showdoc/showdoc
                        
                        (Composer)
                      Mar 16, 2022 
                    
                  
                    
                      File Upload Restriction Bypass leading to Cross-site Scripting in ShowDoc
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0951
                      
                      was published
                        for
                        
                          showdoc/showdoc
                        
                        (Composer)
                      Mar 16, 2022 
                    
                  
                    
                      RuoYi 4.7.3 vulnerable to arbitrary file upload in background management module
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-32065
                      
                      was published
                        for
                        
                          com.ruoyi:ruoyi
                        
                        (Maven)
                      Jul 14, 2022 
                    
                  
                    
                      FeehiCMS Unrestricted Upload vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-36573
                      
                      was published
                        for
                        
                          feehi/feehicms
                        
                        (Composer)
                      Dec 15, 2022 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in yetiforce-crm
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-1411
                      
                      was published
                        for
                        
                          yetiforce/yetiforce-crm
                        
                        (Composer)
                      May 6, 2022 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary Code Execution attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21344
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary Code Execution attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21347
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary Code Execution attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21351
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary Code Execution attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21346
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      XStream is vulnerable to an Arbitrary Code Execution attack
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21350
                      
                      was published
                        for
                        
                          com.thoughtworks.xstream:xstream
                        
                        (Maven)
                      Mar 22, 2021 
                    
                  
                    
                      Unrestricted Uploads in Concrete5
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-14961
                      
                      was published
                        for
                        
                          concrete5/concrete5
                        
                        (Composer)
                      Feb 10, 2022 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in Liferay Portal and Liferay DXP
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-15839
                      
                      was published
                        for
                        
                          com.liferay.portal:release.dxp.bom
                        
                        (Maven)
                      Feb 10, 2022 
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in Umbraco CMS
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-9472
                      
                      was published
                        for
                        
                          UmbracoCms
                        
                        (NuGet)
                      Aug 2, 2021 
                    
                  
                    
                      Improper file handling in matrix-react-sdk
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32622
                      
                      was published
                        for
                        
                          matrix-react-sdk
                        
                        (npm)
                      Feb 10, 2022 
                    
                  
                    
                      Script injection
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32661
                      
                      was published
                        for
                        
                          @backstage/plugin-techdocs
                        
                        (npm)
                      Jun 4, 2021 
                    
                  
                    
                      Script injection
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-32660
                      
                      was published
                        for
                        
                          @backstage/techdocs-common
                        
                        (npm)
                      Jun 4, 2021 
                    
                  
                    
                      Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content.
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-43617
                      
                      was published
                        for
                        
                          laravel/framework
                        
                        (Composer)
                      Nov 16, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Unrestricted Upload of File with Dangerous Type in jsdecena/laracom
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-0472
                      
                      was published
                        for
                        
                          jsdecena/laracom
                        
                        (Composer)
                      Feb 6, 2022 
                    
                  
                    
                      Pimcore contains Unrestricted Upload of File with Dangerous Type
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-23937
                      
                      was published
                        for
                        
                          pimcore/pimcore
                        
                        (Composer)
                      Feb 2, 2023 
                    
                  
                    
                      Mattermost subject to Denial of Service via upload of special GIF
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-3257
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost-server/v6
                        
                        (Go)
                      Sep 25, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API