GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,226
Erlang
31
GitHub Actions
19
Go
1,991
Maven
5,000+
npm
3,708
NuGet
661
pip
3,339
Pub
11
RubyGems
884
Rust
846
Swift
36
Unreviewed advisories
All unreviewed
5,000+
98 advisories
Filter by severity
ConcreteCMS Cross-site Scripting vulnerability
Moderate
CVE-2023-44761
was published
for
concrete5/concrete5
(Composer)
Oct 6, 2023
ConcreteCMS Cross-site Scripting vulnerability
Moderate
CVE-2023-44765
was published
for
concrete5/concrete5
(Composer)
Oct 6, 2023
Stored cross site scripting on API integration
Moderate
CVE-2023-28477
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Concrete CMS missing secure cookie parameters
Moderate
CVE-2023-28472
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Reflected cross site scripting
Moderate
CVE-2023-28475
was published
for
concrete5/concrete5
(Composer)
Apr 28, 2023
Cross-site Scripting vulnerability in drag-and-drop upload of phpMyAdmin
Moderate
CVE-2023-25727
was published
for
phpmyadmin/phpmyadmin
(Composer)
Feb 13, 2023
TYPO3-EXT-SA-2022-018: Multiple vulnerabilities in extension "Master-Quiz" (fp_masterquiz)
Moderate
CVE-2022-47407
was published
for
fixpunkt/fp-masterquiz
(Composer)
Dec 14, 2022
MunkiReport Cross-Site Scripting (XSS) Filter Bypass On Comment
Moderate
CVE-2020-15885
was published
for
munkireport/comment
(Composer)
May 24, 2022
MunkiReport Managed Installs module Reflected Cross-Site Scripting (XSS) vulnerability
Moderate
CVE-2020-15883
was published
for
munkireport/managedinstalls
(Composer)
May 24, 2022
Moodle Open Redirect Vulnerability
Moderate
CVE-2019-10133
was published
for
moodle/moodle
(Composer)
May 24, 2022
Moodle Stored HTML in assignment submission comments allowed links to be opened directly
Moderate
CVE-2019-3850
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle context freezing
Moderate
CVE-2019-3852
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle Secure layout contained an insecure link in Boost theme
Moderate
CVE-2019-3851
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not enforce capability requirements for reading blog comments
Moderate
CVE-2013-2082
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
Moderate
CVE-2013-2083
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not consider "don't send" attributes during hub registration
Moderate
CVE-2013-2081
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle is vulnerable to Sensitive Information Disclosure
Moderate
CVE-2013-2080
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly manage privileges for WebDAV repositories
Moderate
CVE-2013-1836
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows remote authenticated users to reassign notes
Moderate
CVE-2013-1834
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not enforce the forceloginforprofiles setting
Moderate
CVE-2013-1830
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle includes the WebDAV password in the configuration form
Moderate
CVE-2013-1832
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle reveals absolute path in exception message
Moderate
CVE-2013-1831
was published
for
moodle/moodle
(Composer)
May 13, 2022
PHP Spellchecker addon for TinyMCE allows attackers to trigger arbitrary outbound HTTP requests
Moderate
CVE-2012-6112
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Moderate
CVE-2014-0218
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2014-0126
was published
for
moodle/moodle
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API