GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
255 advisories
Filter by severity
Dolibarr sensitive information disclosure
High
CVE-2017-17898
was published
for
dolibarr/dolibarr
(Composer)
May 14, 2022
Moodle Privilege escalation in quiz web services
Moderate
CVE-2018-1044
was published
for
moodle/moodle
(Composer)
May 14, 2022
Drupal Comment reply form allows access to restricted content
High
CVE-2017-6926
was published
for
drupal/core
(Composer)
May 14, 2022
Moodle Portfolio forum caller class allows a user to download any file
Moderate
CVE-2018-1135
was published
for
moodle/moodle
(Composer)
May 14, 2022
Converse.js Exposure of Sensitive Information
Moderate
CVE-2018-6591
was published
for
converse.js
(Composer)
May 14, 2022
Sensitive Data Exposure in baserCMS
Moderate
CVE-2018-0575
was published
for
baserproject/basercms
(Composer)
May 14, 2022
SimpleSAMLphp Information leakage issue in the sanitycheck module
Moderate
CVE-2016-3124
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
DOMPDF Arbitrary File Read
Moderate
CVE-2014-2383
was published
for
dompdf/dompdf
(Composer)
May 14, 2022
phpMyAdmin full path disclosure vulnerability
Moderate
CVE-2016-5730
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
phpMyAdmin vulnerable to Cross-Site Request Forgery
High
CVE-2016-5739
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
LFI in PHP-Proxy 5.1.0
High
CVE-2018-19246
was published
for
athlon1600/php-proxy
(Composer)
May 14, 2022
Showdoc Forced Browsing
Moderate
CVE-2018-19609
was published
for
showdoc/showdoc
(Composer)
May 14, 2022
Flarum Core Leaks PII
Moderate
CVE-2018-19133
was published
for
flarum/framework
(Composer)
May 14, 2022
phpMyAdmin Local file inclusion through transformation feature
Moderate
CVE-2018-19968
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
SimpleSAMLphp allows timing side-channel attacks
Moderate
CVE-2017-12872
was published
for
simplesamlphp/simplesamlphp
(Composer)
May 14, 2022
Anchor CMS Logs Credentials
Critical
CVE-2018-7251
was published
for
anchorcms/anchor-cms
(Composer)
May 13, 2022
Moodle Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2018-10890
was published
for
moodle/moodle
(Composer)
May 13, 2022
The Direct Mail (direct_mail) TYPO3 extension improperly discloses sensitive information
High
CVE-2013-7400
was published
for
directmailteam/direct-mail
(Composer)
May 13, 2022
October CMS Local File Inclusion
High
CVE-2018-1999009
was published
for
october/october
(Composer)
May 13, 2022
Moodle does not recogniz configuration setting that makes e-mail addresses visible only to course members
Moderate
CVE-2011-4289
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows remote attackers to obtain sensitive information from myprofile block by visiting user-context page
Moderate
CVE-2011-4284
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not use the forceloginforprofiles setting for course-profiles access control
Moderate
CVE-2011-4279
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows remote attackers to obtain sensitive information
Moderate
CVE-2011-4283
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Exposes Sensitive User Information
Moderate
CVE-2012-2353
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle's login_as feature leaks information from external repositories
Low
CVE-2013-1835
was published
for
moodle/moodle
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API