Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

153 advisories

Loading
Admidio Improper Access Control vulnerability Moderate
CVE-2023-3304 was published for admidio/admidio (Composer) Jun 23, 2023
TeamPass vulnerable to Improper Access Control Moderate
CVE-2023-3095 was published for nilsteampassnet/teampass (Composer) Jun 4, 2023
phpMyFAQ Improper Access Control vulnerability Moderate
CVE-2023-2429 was published for thorsten/phpmyfaq (Composer) Apr 30, 2023
RosarioSIS improper access control vulnerability Moderate
CVE-2023-2202 was published for francoisjacquet/rosariosis (Composer) Apr 21, 2023
alextselegidis/easyappointments Improper Access Control vulnerability Moderate
CVE-2023-2104 was published for alextselegidis/easyappointments (Composer) Apr 15, 2023
thorsten/phpmyfaq vulnerable to improper access control Moderate
CVE-2023-1883 was published for thorsten/phpmyfaq (Composer) Apr 5, 2023
Magento Open Source allows Improper Access Control Moderate
CVE-2023-22250 was published for magento/community-edition (Composer) Mar 27, 2023
RosarioSIS Improper Access Control vulnerability High
CVE-2023-0994 was published for francoisjacquet/rosariosis (Composer) Feb 24, 2023
Moodle Improper Access Control vulnerability High
CVE-2023-23923 was published for moodle/moodle (Composer) Feb 17, 2023
Flarum post mentions can be used to read any post on the forum without access control High
CVE-2023-22487 was published for flarum/mentions (Composer) Jan 10, 2023
clarkwinkelmann Credited to clarkwinkelmann
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz) Moderate
CVE-2022-47407 was published for fixpunkt/fp-masterquiz (Composer) Dec 14, 2022
MarkLee131 Credited to MarkLee131
easyii CMS's File Upload Management vulnerable to unrestricted upload Critical
CVE-2022-3771 was published for noumo/easyii (Composer) Oct 31, 2022
Magento Open Source allows Improper Access Control Moderate
CVE-2022-35689 was published for magento/community-edition (Composer) Oct 15, 2022
Magento Improper Access Control vulnerability High
CVE-2022-34255 was published for magento/community-edition (Composer) Aug 17, 2022
Magento Improper Access Control vulnerability Moderate
CVE-2022-34259 was published for magento/community-edition (Composer) Aug 17, 2022
JetPack Exposure of Resource to Wrong Sphere Moderate
CVE-2021-24374 was published for automattic/jetpack (Composer) May 24, 2022
Magento Improper Access Control Moderate
CVE-2021-21020 was published for magento/community-edition (Composer) May 24, 2022
Moodle incorrect access control High
CVE-2020-25629 was published for moodle/moodle (Composer) May 24, 2022
moodle Improper Access Control Moderate
CVE-2019-10189 was published for moodle/moodle (Composer) May 24, 2022
Moodle Ability to delete glossary entries that belong to another glossary Moderate
CVE-2019-10187 was published for moodle/moodle (Composer) May 24, 2022
moodle Improper Access Control Moderate
CVE-2019-10188 was published for moodle/moodle (Composer) May 24, 2022
Wikimedia MediaWik exposed suppressed log in RevisionDelete page Moderate
CVE-2019-12470 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Incorrect Access Control vulnerability Moderate
CVE-2019-12469 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Incorrect Access Control vulnerability High
CVE-2019-12472 was published for mediawiki/core (Composer) May 24, 2022
MediaWiki Incorrect Access Control vulnerability Moderate
CVE-2019-12467 was published for mediawiki/core (Composer) May 24, 2022
ProTip! Advisories are also available from the GraphQL API