GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,224
Erlang
31
GitHub Actions
19
Go
1,990
Maven
5,000+
npm
3,706
NuGet
661
pip
3,336
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,361 advisories
Filter by severity
Moodle allows attackers to extract archives to arbitrary directories
Moderate
CVE-2015-2267
was published
for
moodle/moodle
(Composer)
May 13, 2022
In Moodle 2.x and 3.x, non-admin site managers may accidentally edit admins via web services.
Moderate
Unreviewed
CVE-2016-8643
was published
May 13, 2022
Moodle Unauthenticated Access
Moderate
CVE-2016-8642
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Improper Access Control
Moderate
CVE-2016-3733
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Improper Access Control
Moderate
CVE-2016-3729
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle External function mod_assign_save_submission does not check due dates
Moderate
CVE-2016-2159
was published
for
moodle/moodle
(Composer)
May 13, 2022
It was found that system umask policy is not being honored when creating XDG user directories,...
High
Unreviewed
CVE-2017-15131
was published
May 13, 2022
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files...
High
Unreviewed
CVE-2015-3306
was published
May 13, 2022
The Apache HTTP Server 2.4.18 through 2.4.20, when mod_http2 and mod_ssl are enabled, does not...
High
Unreviewed
CVE-2016-4979
was published
May 13, 2022
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not...
High
Unreviewed
CVE-2016-5387
was published
May 13, 2022
Improper Access Control in Apache CXF
Moderate
CVE-2015-5253
was published
for
org.apache.cxf:cxf-rt-rs-security-sso-saml
(Maven)
May 13, 2022
puppet-tripleo before versions 5.5.0, 6.2.0 is vulnerable to an access-control flaw in the...
High
Unreviewed
CVE-2016-9599
was published
May 13, 2022
Microsoft Outlook 2007 SP3, Outlook 2010 SP2, Outlook 2013 SP1, Outlook 2013 RT SP1, Outlook 2016...
Moderate
Unreviewed
CVE-2016-3366
was published
May 13, 2022
Puppet Improper Access Control
Critical
CVE-2016-2785
was published
for
puppet
(RubyGems)
May 13, 2022
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary...
Critical
Unreviewed
CVE-2016-3987
was published
May 13, 2022
MCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers...
Critical
Unreviewed
CVE-2016-2788
was published
May 13, 2022
Improper Access Control in SLF4J
Critical
CVE-2018-8088
was published
for
org.slf4j:slf4j-ext
(Maven)
May 13, 2022
An issue was discovered in Pivotal RabbitMQ 3.x before 3.5.8 and 3.6.x before 3.6.6 and RabbitMQ...
Critical
Unreviewed
CVE-2016-9877
was published
May 13, 2022
Improper Access Control in Apache Derby
Moderate
CVE-2018-1313
was published
for
org.apache.derby:derby
(Maven)
May 13, 2022
A privilege escalation vulnerability exists in the router configuration import functionality of...
High
Unreviewed
CVE-2022-21182
was published
May 13, 2022
Incorrect Authorization in microweber
High
CVE-2022-1631
was published
for
microweber/microweber
(Composer)
May 10, 2022
Improper Access Control in wp-graphql
Moderate
CVE-2019-25060
was published
for
wp-graphql/wp-graphql
(Composer)
May 10, 2022
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an...
Critical
Unreviewed
CVE-2022-20777
was published
May 5, 2022
The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter...
High
Unreviewed
CVE-2009-5151
was published
May 2, 2022
Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the...
High
Unreviewed
CVE-2009-5150
was published
May 2, 2022
ProTip!
Advisories are also available from the
GraphQL API