GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
119 advisories
Filter by severity
phpMyAdmin vulnerable to static code injection
High
CVE-2011-2506
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code
High
CVE-2014-3942
was published
for
typo3/cms
(Composer)
May 14, 2022
Zeta Components Mail Arbitrary code execution via a crafted email address
High
CVE-2017-15806
was published
for
zetacomponents/mail
(Composer)
May 17, 2022
GeniXCMS arbitrary PHP code execution
High
CVE-2017-14764
was published
for
genix/cms
(Composer)
May 17, 2022
Smarty arbitrary PHP code execution
High
CVE-2014-8350
was published
for
smarty/smarty
(Composer)
May 17, 2022
Symfony Arbitrary PHP code Execution
High
CVE-2013-1397
was published
for
symfony/symfony
(Composer)
May 17, 2022
Symphony Vulnerable to PHP Code Injection via YAML Parsing
High
CVE-2013-1348
was published
for
symfony/symfony
(Composer)
May 17, 2022
Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands
High
CVE-2010-4962
was published
for
dmk/webkitpdf
(Composer)
May 17, 2022
Authenticated RCE in Zen Cart 1.5.5e
High
CVE-2017-11675
was published
for
zencart/zencart
(Composer)
May 17, 2022
phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension
High
CVE-2016-6633
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Slim vulnerable to PHP object injection
High
CVE-2015-2171
was published
for
slim/slim
(Composer)
May 17, 2022
Drupal arbitrary code execution
High
CVE-2016-3171
was published
for
drupal/core
(Composer)
May 17, 2022
TYPO3 powermail extension has unrestricted file upload vulnerability
High
CVE-2014-3947
was published
for
in2code/powermail
(Composer)
May 17, 2022
Yii PHP Framework arbitrary PHP scripts execution
High
CVE-2014-4672
was published
for
yiisoft/yii
(Composer)
May 17, 2022
TYPO3 vulnerable to remote authenticated arbitrary code execution
High
CVE-2013-4321
was published
for
typo3/cms
(Composer)
May 17, 2022
Pimcore Vulnerable to PHP Object Injection Attacks
High
CVE-2014-2921
was published
for
pimcore/pimcore
(Composer)
May 17, 2022
phpMyAdmin Remote Code Execution
High
CVE-2013-3239
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
EGroupware Code Injection vulnerability
High
CVE-2010-3313
was published
for
egroupware/egroupware
(Composer)
May 17, 2022
ImpressPages CMS eval injection vulnerability
High
CVE-2011-4932
was published
for
impresspages/impresspages
(Composer)
May 17, 2022
DOMPDF Remote File Inclusion Vulnerability
High
CVE-2010-4879
was published
for
dompdf/dompdf
(Composer)
May 17, 2022
DOMPDF Remote Code Execution
High
CVE-2014-5013
was published
for
dompdf/dompdf
(Composer)
May 17, 2022
Dolibarr ERP and CRM Code Injection
High
CVE-2019-11201
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Magento 2 Community Edition Unsafe File Upload
High
CVE-2019-7871
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-7903
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-7932
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API