GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,781
Erlang
36
GitHub Actions
29
Go
2,345
Maven
5,000+
npm
3,976
NuGet
719
pip
3,772
Pub
12
RubyGems
923
Rust
980
Swift
38
Unreviewed advisories
All unreviewed
5,000+
113 advisories
Filter by severity
TYPO3 powermail extension has unrestricted file upload vulnerability
High
CVE-2014-3947
was published
for
in2code/powermail
(Composer)
May 17, 2022
Drupal arbitrary code execution
High
CVE-2016-3171
was published
for
drupal/core
(Composer)
May 17, 2022
Slim vulnerable to PHP object injection
High
CVE-2015-2171
was published
for
slim/slim
(Composer)
May 17, 2022
phpMyAdmin Remote code execution vulnerability when PHP is running with dbase extension
High
CVE-2016-6633
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Authenticated RCE in Zen Cart 1.5.5e
High
CVE-2017-11675
was published
for
zencart/zencart
(Composer)
May 17, 2022
Webkit PDFs for TYPO3 allows remote attackers to execute arbitrary commands
High
CVE-2010-4962
was published
for
dmk/webkitpdf
(Composer)
May 17, 2022
Symphony Vulnerable to PHP Code Injection via YAML Parsing
High
CVE-2013-1348
was published
for
symfony/symfony
(Composer)
May 17, 2022
Symfony Arbitrary PHP code Execution
High
CVE-2013-1397
was published
for
symfony/symfony
(Composer)
May 17, 2022
Smarty arbitrary PHP code execution
High
CVE-2014-8350
was published
for
smarty/smarty
(Composer)
May 17, 2022
GeniXCMS arbitrary PHP code execution
High
CVE-2017-14764
was published
for
genix/cms
(Composer)
May 17, 2022
Zeta Components Mail Arbitrary code execution via a crafted email address
High
CVE-2017-15806
was published
for
zetacomponents/mail
(Composer)
May 17, 2022
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code
High
CVE-2014-3942
was published
for
typo3/cms
(Composer)
May 14, 2022
phpMyAdmin vulnerable to static code injection
High
CVE-2011-2506
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 14, 2022
PHPMailer susceptible to arbitrary code execution
High
CVE-2008-5619
was published
for
phpmailer/phpmailer
(Composer)
May 14, 2022
PrestaShop PHP Object Injection
High
CVE-2018-20717
was published
for
prestashop/prestashop
(Composer)
May 14, 2022
Code Injection in baserCMS
High
CVE-2017-10844
was published
for
baserproject/basercms
(Composer)
May 14, 2022
MAGMI plugin for Magento Unsafe File Upload
High
CVE-2014-8770
was published
for
dweeves/magmi
(Composer)
May 14, 2022
Moodle XML import of ddwtos could lead to intentional remote code execution
High
CVE-2018-14630
was published
for
moodle/moodle
(Composer)
May 13, 2022
SEOmatic plugin for Craft CMS SSTI Vulnerability
High
CVE-2018-14716
was published
for
nystudio107/craft-seomatic
(Composer)
May 13, 2022
Moodle calculated question type allows remote code execution by Question authors
High
CVE-2018-1133
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle vulnerable to PHP object injection attacks
High
CVE-2014-3541
was published
for
moodle/moodle
(Composer)
May 13, 2022
TYPO3 PHP remote file inclusion vulnerability
High
CVE-2010-1153
was published
for
typo3/cms
(Composer)
May 2, 2022
TYPO3 Backend Command Injection via Shell Metacharacters in Uploaded File Name
High
CVE-2009-3631
was published
for
typo3/cms-backend
(Composer)
May 2, 2022
Missing input validation can lead to command execution in composer
High
CVE-2022-24828
was published
for
composer/composer
(Composer)
Apr 22, 2022
ProTip!
Advisories are also available from the
GraphQL API