GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,359
Erlang
33
GitHub Actions
22
Go
2,127
Maven
5,000+
npm
3,793
NuGet
683
pip
3,471
Pub
12
RubyGems
894
Rust
894
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,496 advisories
Filter by severity
MongoDB Driver may publish events containing authentication-related data
Moderate
CVE-2021-32050
was published
for
github.com/mongodb/mongo-swift-driver
(Composer)
Aug 29, 2023
Uvdesk vulnerable to stored cross-site scripting (XSS)
Moderate
CVE-2023-0325
was published
for
uvdesk/community-skeleton
(Composer)
Apr 5, 2023
Symfony storing cookie headers in HttpCache
Moderate
CVE-2022-24894
was published
for
symfony/http-kernel
(Composer)
Feb 1, 2023
Magento Open Source has Improper Access Control vulnerability
Moderate
CVE-2022-35692
was published
for
magento/community-edition
(Composer)
Aug 20, 2022
Pimcore Admin Classic Bundle allows user enumeration
Moderate
CVE-2025-24980
was published
for
pimcore/admin-ui-classic-bundle
(Composer)
Feb 7, 2025
Moodle vulnerable to cache poisoning via injection into storage
Moderate
CVE-2024-43428
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
Moodle has arbitrary file read risk through pdfTeX
Moderate
CVE-2024-43426
was published
for
moodle/moodle
(Composer)
Nov 7, 2024
Magento Improper Authorization vulnerability in the customers module
Moderate
CVE-2021-28567
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento DOM-based Cross-Site Scripting vulnerability on mage-messages cookies
Moderate
CVE-2021-28556
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Path Traversal vulnerability
Moderate
CVE-2021-28584
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Improper input validation vulnerability
Moderate
CVE-2021-28585
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Insufficient Session Expiration
Moderate
CVE-2021-21031
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Insufficient Session Expiration
Moderate
CVE-2021-21032
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability in the admin console
Moderate
CVE-2021-21023
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento cross-site request forgery (CSRF) vulnerability via the GraphQL API
Moderate
CVE-2021-21027
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento improper authorization vulnerability in the integrations module
Moderate
CVE-2021-21026
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Insecure Direct Object Reference (IDOR) in the product module
Moderate
CVE-2021-21022
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Improper Access Control
Moderate
CVE-2021-21020
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Incorrect Authorization
Moderate
CVE-2020-24401
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento incorrect permissions vulnerability in the Integrations component
Moderate
CVE-2020-24402
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento path traversal vulnerability
Moderate
CVE-2020-9689
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Stored cross-site scripting
Moderate
CVE-2020-9584
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-9581
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento stored cross-site scripting vulnerability
Moderate
CVE-2020-9577
was published
for
magento/community-edition
(Composer)
May 24, 2022
Stored XSS in REDAXO
Moderate
CVE-2024-13209
was published
for
redaxo/source
(Composer)
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API