GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,383
Erlang
33
GitHub Actions
22
Go
2,141
Maven
5,000+
npm
3,803
NuGet
687
pip
3,479
Pub
12
RubyGems
897
Rust
898
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,177 advisories
Filter by severity
Moodle has an arbitrary file read risk through pdfTeX
High
CVE-2025-26525
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a stored XSS risk in admin live log
High
CVE-2025-26529
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle has a SQL injection risk in course search module list filter
High
CVE-2025-26533
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Moodle allows reflected XSS via question bank filter
High
CVE-2025-26530
was published
for
moodle/moodle
(Composer)
Feb 24, 2025
Leantime allows Stored Cross-Site Scripting (XSS)
High
GHSA-c39w-3pjx-qc7m
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Leantime allows Cross Site Scripting (XSS) and SQL Injection (SQLi)
High
GHSA-v4q9-437p-mhpg
was published
for
leantime/leantime
(Composer)
Feb 21, 2025
Connect-CMS information that is restricted to viewing is visible
High
GHSA-2237-5r9w-vm8j
was published
for
opensource-workshop/connect-cms
(Composer)
Feb 7, 2025
Cockpit Arbitrary File Upload
High
CVE-2025-1025
was published
for
cockpit-hq/cockpit
(Composer)
Feb 5, 2025
Browsershot Path Traversal
High
CVE-2025-1022
was published
for
spatie/browsershot
(Composer)
Feb 5, 2025
DevDojo Voyager vulnerable to path traversal
High
CVE-2024-55415
was published
for
tcg/voyager
(Composer)
Jan 30, 2025
Pimcore Authenticated Stored Cross-Site Scripting (XSS) Via Search Document
High
GHSA-xr3m-6gq6-22cg
was published
for
pimcore/pimcore
(Composer)
Jan 28, 2025
Authenticated arbitrary file deletion in YesWiki
High
CVE-2025-24019
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Authenticated Stored XSS in YesWiki
High
CVE-2025-24018
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Unauthenticated DOM Based XSS in YesWiki
High
CVE-2025-24017
was published
for
yeswiki/yeswiki
(Composer)
Jan 21, 2025
Craft CMS has a potential RCE with a compromised security key
High
CVE-2025-23209
was published
for
craftcms/cms
(Composer)
Jan 21, 2025
TYPO3 Scheduler Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55924
was published
for
typo3/cms-scheduler
(Composer)
Jan 14, 2025
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
High
CVE-2024-55921
was published
for
typo3/cms-extensionmanager
(Composer)
Jan 14, 2025
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
Extension:TabberNeue vulnerable to Cross-site Scripting
High
CVE-2025-21612
was published
for
starcitizentools/tabber-neue
(Composer)
Jan 6, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
High
CVE-2024-56409
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
High
CVE-2024-56366
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
High
CVE-2024-56365
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
High
CVE-2024-56408
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
TCPDF has incorrect comparison
High
CVE-2024-56522
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
TCPDF missing certificate validation
High
CVE-2024-56521
was published
for
tecnickcom/tcpdf
(Composer)
Dec 27, 2024
ProTip!
Advisories are also available from the
GraphQL API