GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
196 advisories
Filter by severity
Craft CMS has a potential RCE with a compromised security key
High
CVE-2025-23209
was published
for
craftcms/cms
(Composer)
Jan 21, 2025
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
Critical
CVE-2024-56145
was published
for
craftcms/cms
(Composer)
Dec 18, 2024
Unauthenticated remote code execution in Ignition
Critical
CVE-2021-3129
was published
for
facade/ignition
(Composer)
Mar 29, 2021
Drupal Core Remote Code Execution Vulnerability
Critical
CVE-2018-7602
was published
for
drupal/core
(Composer)
Apr 23, 2024
Code Injection in PHPUnit
Critical
CVE-2017-9841
was published
for
phpunit/phpunit
(Composer)
Mar 26, 2022
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
Mautic allows Remote Code Execution and File Deletion in Asset Uploads
Critical
CVE-2024-47051
was published
for
mautic/core
(Composer)
Feb 26, 2025
Dolibarr vulnerable to RCE via the computed field parameter
High
CVE-2025-56588
was published
for
dolibarr/dolibarr
(Composer)
Oct 1, 2025
TYPO3 Install Tool vulnerable to Code Execution
High
CVE-2024-22188
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
The Freeform CraftCMS plugin contains an Server-side template injection (SSTI) vulnerability
Critical
CVE-2025-52122
was published
for
solspace/craft-freeform
(Composer)
Aug 27, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
High
CVE-2024-52293
was published
for
craftcms/cms
(Composer)
Nov 13, 2024
Bolt CMS vulnerable to authenticated remote code execution
High
CVE-2025-34086
was published
for
bolt/bolt
(Composer)
Jul 3, 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Critical
CVE-2025-49132
was published
for
pterodactyl/panel
(Composer)
Jun 19, 2025
Dolibarr vulnerable to Eval Injection
Critical
CVE-2022-40871
was published
for
dolibarr/dolibarr
(Composer)
Oct 12, 2022
Froxlor vulnerable to Code Injection
Moderate
CVE-2022-3721
was published
for
froxlor/froxlor
(Composer)
Nov 4, 2022
Badaso vulnerable to Remote Code Execution (RCE)
Critical
CVE-2022-41705
was published
for
badaso/core
(Composer)
Nov 25, 2022
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
High
CVE-2025-3642
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
High
CVE-2025-3641
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Craft CMS Allows Remote Code Execution
Critical
CVE-2025-32432
was published
for
craftcms/cms
(Composer)
Apr 25, 2025
phpMyAdmin Code Injection vulnerability
Critical
CVE-2016-5734
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
TYPO3 powermail extension has unrestricted file upload vulnerability
High
CVE-2014-3947
was published
for
in2code/powermail
(Composer)
May 17, 2022
TYPO3 Color Picker Wizard component allows remote authenticated editors to execute arbitrary PHP code
High
CVE-2014-3942
was published
for
typo3/cms
(Composer)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API