GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,179
Erlang
31
GitHub Actions
19
Go
1,982
Maven
5,000+
npm
3,701
NuGet
656
pip
3,323
Pub
11
RubyGems
882
Rust
834
Swift
35
Unreviewed advisories
All unreviewed
5,000+
2,399 advisories
Filter by severity
No Restriction of Excessive Authentication Attempts in Firefly III
Moderate
CVE-2021-3663
was published
for
grumpydictator/firefly-iii
(Composer)
Aug 9, 2021
Incorrect Authorization in TYPO3 extension
Moderate
CVE-2020-25025
was published
for
localizationteam/l10nmgr
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12700
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Missing Authorization in TYPO3 extension
Moderate
CVE-2020-12698
was published
for
directmailteam/direct-mail
(Composer)
Jul 26, 2021
Information Disclosure in User Authentication
Moderate
CVE-2021-32767
was published
for
typo3/cms
(Composer)
Jul 26, 2021
Cross-Site Scripting in Backend Grid View
Moderate
CVE-2021-32669
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Query Generator & Query View
Moderate
CVE-2021-32668
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-Site Scripting in Page Preview
Moderate
CVE-2021-32667
was published
for
typo3/cms
(Composer)
Jul 22, 2021
Cross-site Scripting in Froala WYSIWYG Editor
Moderate
CVE-2021-28114
was published
for
froala/wysiwyg-editor
(Composer)
Jul 19, 2021
Craft CMS Cross-site Scripting Vulnerability
Moderate
CVE-2021-27902
was published
for
craftcms/cms
(Composer)
Jul 2, 2021
XSS Injection in Media Collection Title was possible
Moderate
CVE-2021-32737
was published
for
sulu/sulu
(Composer)
Jul 2, 2021
Cross site scripting in the system log
Moderate
CVE-2021-35210
was published
for
contao/contao
(Composer)
Jul 1, 2021
Missing Authentication for Critical Function
Moderate
CVE-2021-32709
was published
for
shopware/platform
(Composer)
Jun 29, 2021
List of order ids, number, items total and token value exposed for unauthorized uses via new API
Moderate
CVE-2021-32720
was published
for
sylius/sylius
(Composer)
Jun 29, 2021
non-admin users can create integration role with administrator role
Moderate
GHSA-243q-g9j3-qf6r
was published
for
shopware/core
(Composer)
Jun 28, 2021
Internal hidden fields are visible on to many associations in admin api
Moderate
GHSA-gpmh-g94g-qrhr
was published
for
shopware/core
(Composer)
Jun 28, 2021
Canceling of orders not related to the logged-in user
Moderate
GHSA-wq3r-jwrq-xg6w
was published
for
shopware/core
(Composer)
Jun 28, 2021
Cross-site Scripting in yii2cmf
Moderate
CVE-2018-10704
was published
for
yidashi/yii2cmf
(Composer)
Jun 22, 2021
Session Fixation in Subrion CMS
Moderate
CVE-2020-12467
was published
for
intelliants/subrion
(Composer)
Jun 22, 2021
Cross-site scripting in PageKit
Moderate
CVE-2021-32245
was published
for
pagekit/pagekit
(Composer)
Jun 22, 2021
Form validation can be skipped
Moderate
CVE-2021-32697
was published
for
neos/form
(Composer)
Jun 22, 2021
ckeditor4 vulnerable to cross-site scripting
Moderate
CVE-2021-33829
was published
for
ckeditor4
(Composer)
Jun 21, 2021
Authentication granted to all firewalls instead of just one
Moderate
CVE-2021-32693
was published
for
symfony/security-http
(Composer)
Jun 21, 2021
Authentication bypass in SilverStripe GraphQL
Moderate
CVE-2020-26136
was published
for
silverstripe/graphql
(Composer)
Jun 10, 2021
Cross-site scripting in Centreon
Moderate
CVE-2021-27676
was published
for
centreon/centreon
(Composer)
Jun 8, 2021
ProTip!
Advisories are also available from the
GraphQL API