GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
153 advisories
Filter by severity
Admidio Improper Access Control vulnerability
Moderate
CVE-2023-3304
was published
for
admidio/admidio
(Composer)
Jun 23, 2023
TeamPass vulnerable to Improper Access Control
Moderate
CVE-2023-3095
was published
for
nilsteampassnet/teampass
(Composer)
Jun 4, 2023
phpMyFAQ Improper Access Control vulnerability
Moderate
CVE-2023-2429
was published
for
thorsten/phpmyfaq
(Composer)
Apr 30, 2023
RosarioSIS improper access control vulnerability
Moderate
CVE-2023-2202
was published
for
francoisjacquet/rosariosis
(Composer)
Apr 21, 2023
alextselegidis/easyappointments Improper Access Control vulnerability
Moderate
CVE-2023-2104
was published
for
alextselegidis/easyappointments
(Composer)
Apr 15, 2023
thorsten/phpmyfaq vulnerable to improper access control
Moderate
CVE-2023-1883
was published
for
thorsten/phpmyfaq
(Composer)
Apr 5, 2023
Magento Open Source allows Improper Access Control
Moderate
CVE-2023-22250
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
RosarioSIS Improper Access Control vulnerability
High
CVE-2023-0994
was published
for
francoisjacquet/rosariosis
(Composer)
Feb 24, 2023
Moodle Improper Access Control vulnerability
High
CVE-2023-23923
was published
for
moodle/moodle
(Composer)
Feb 17, 2023
Flarum post mentions can be used to read any post on the forum without access control
High
CVE-2023-22487
was published
for
flarum/mentions
(Composer)
Jan 10, 2023
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
Moderate
CVE-2022-47407
was published
for
fixpunkt/fp-masterquiz
(Composer)
Dec 14, 2022
easyii CMS's File Upload Management vulnerable to unrestricted upload
Critical
CVE-2022-3771
was published
for
noumo/easyii
(Composer)
Oct 31, 2022
Magento Open Source allows Improper Access Control
Moderate
CVE-2022-35689
was published
for
magento/community-edition
(Composer)
Oct 15, 2022
Magento Improper Access Control vulnerability
High
CVE-2022-34255
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento Improper Access Control vulnerability
Moderate
CVE-2022-34259
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
JetPack Exposure of Resource to Wrong Sphere
Moderate
CVE-2021-24374
was published
for
automattic/jetpack
(Composer)
May 24, 2022
Magento Improper Access Control
Moderate
CVE-2021-21020
was published
for
magento/community-edition
(Composer)
May 24, 2022
Moodle incorrect access control
High
CVE-2020-25629
was published
for
moodle/moodle
(Composer)
May 24, 2022
moodle Improper Access Control
Moderate
CVE-2019-10189
was published
for
moodle/moodle
(Composer)
May 24, 2022
Moodle Ability to delete glossary entries that belong to another glossary
Moderate
CVE-2019-10187
was published
for
moodle/moodle
(Composer)
May 24, 2022
moodle Improper Access Control
Moderate
CVE-2019-10188
was published
for
moodle/moodle
(Composer)
May 24, 2022
Wikimedia MediaWik exposed suppressed log in RevisionDelete page
Moderate
CVE-2019-12470
was published
for
mediawiki/core
(Composer)
May 24, 2022
MediaWiki Incorrect Access Control vulnerability
Moderate
CVE-2019-12469
was published
for
mediawiki/core
(Composer)
May 24, 2022
MediaWiki Incorrect Access Control vulnerability
High
CVE-2019-12472
was published
for
mediawiki/core
(Composer)
May 24, 2022
MediaWiki Incorrect Access Control vulnerability
Moderate
CVE-2019-12467
was published
for
mediawiki/core
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API