GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
257 advisories
Filter by severity
Moodle provides calendar-event data without considering whether an activity is hidden
Moderate
CVE-2016-2156
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle sensitive information disclosure
Moderate
CVE-2016-3732
was published
for
moodle/moodle
(Composer)
May 13, 2022
Sensitive Data Exposure in elFinder
Moderate
CVE-2019-5884
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
TYPO3 Simple Download-System with Counter and Categories Vulnerable to Information Disclosure
Moderate
CVE-2009-4160
was published
for
jweiland/kk-downloader
(Composer)
May 2, 2022
TYPO3 Backend Discloses Encryption Key
Moderate
CVE-2009-3628
was published
for
typo3/cms-backend
(Composer)
May 2, 2022
TYPO3 leaks a hash secret in an error message
Moderate
CVE-2009-0815
was published
for
typo3/cms
(Composer)
May 2, 2022
TYPO3 Reveals Sensitive Information via Direct Request to `misc/phpcheck/`
High
CVE-2005-4875
was published
for
typo3/cms
(Composer)
May 1, 2022
Moodle included private user files in course backups
Moderate
CVE-2012-1159
was published
for
moodle/moodle
(Composer)
Apr 23, 2022
Typo3 Information Disclosure
Moderate
CVE-2011-4900
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Typo3 Arbitrary Information Disclosure
Moderate
CVE-2011-4901
was published
for
typo3/cms
(Composer)
Apr 22, 2022
Typo3 Information Disclosure
Moderate
CVE-2011-4627
was published
for
typo3/cms
(Composer)
Apr 22, 2022
TYPO3 is vulnerable to Information Disclosure in the HTML mailing API
Moderate
CVE-2010-3673
was published
for
typo3/cms-core
(Composer)
Apr 21, 2022
TYPO3 is vulnerable to Information Disclosure on the backend
Moderate
CVE-2010-3664
was published
for
typo3/cms-backend
(Composer)
Apr 21, 2022
Discoverability of user password hash in Statamic CMS
Low
CVE-2022-24784
was published
for
statamic/cms
(Composer)
Mar 29, 2022
Twig Sandbox Information Disclosure
Low
CVE-2019-9942
was published
for
twig/twig
(Composer)
Mar 26, 2022
Sensitive Information Exposure in Sylius
Moderate
CVE-2022-24742
was published
for
sylius/sylius
(Composer)
Mar 14, 2022
Moodle Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2021-32477
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Moodle Exposure of Sensitive Information to an Unauthorized Actor
Moderate
CVE-2021-32472
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Moodle Information Disclosure vulnerability
Moderate
CVE-2021-32473
was published
for
moodle/moodle
(Composer)
Mar 12, 2022
Exposure of Sensitive Information to an Unauthorized Actor in PhpMyAdmin
High
CVE-2022-0813
was published
for
phpmyadmin/phpmyadmin
(Composer)
Mar 11, 2022
HTTP caching is marking private HTTP headers as public in Shopware
Moderate
CVE-2022-24747
was published
for
shopware/core
(Composer)
Mar 10, 2022
Exposure of Sensitive Information to an Unauthorized Actor in librenms
Moderate
CVE-2022-0588
was published
for
librenms/librenms
(Composer)
Feb 16, 2022
Exposure of Sensitive Information in snipe/snipe-it
Moderate
CVE-2022-0569
was published
for
snipe/snipe-it
(Composer)
Feb 15, 2022
Exposure of Sensitive Information to an Unauthorized Actor in pimcore
Moderate
CVE-2022-0565
was published
for
pimcore/pimcore
(Composer)
Feb 15, 2022
Exposure of Sensitive Information to an Unauthorized Actor in microweber
High
CVE-2022-0281
was published
for
microweber/microweber
(Composer)
Jan 21, 2022
ProTip!
Advisories are also available from the
GraphQL API