GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
139 advisories
Filter by severity
slub_events for Typo3 Arbitrary File Upload
Critical
CVE-2019-16700
was published
for
slub/slub-events
(Composer)
May 24, 2022
Pimcore Unrestricted Upload of File with Dangerous Type
High
CVE-2019-16318
was published
for
pimcore/pimcore
(Composer)
May 24, 2022
Magento 2 Community Unrestricted File Upload
High
CVE-2019-7930
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Filter extension bypass via crafted store configuration keys
High
CVE-2019-7912
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Unsafe File Upload
High
CVE-2019-7861
was published
for
magento/community-edition
(Composer)
May 24, 2022
Arbitrary file upload in ShopXO
High
CVE-2021-41938
was published
for
shopxo/shopxo
(Composer)
May 20, 2022
jQuery File Upload Plugin Unrestricted file upload vulnerability
High
CVE-2014-8739
was published
for
blueimp/jquery-file-upload
(Composer)
May 17, 2022
Moodle Unrestricted file upload vulnerability
High
CVE-2016-9187
was published
for
moodle/moodle
(Composer)
May 17, 2022
Dolibarr ERP and CRM Unsafe File Upload Vulnerability
High
CVE-2017-9840
was published
for
dolibarr/dolibarr
(Composer)
May 17, 2022
TYPO3 Arbitrary Code Execution
High
CVE-2017-14251
was published
for
typo3/cms
(Composer)
May 17, 2022
TeamPass arbitrary file upload vulnerability
High
CVE-2017-15054
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
baserCMS arbitrary file upload vulnerability
Moderate
CVE-2018-0571
was published
for
baserproject/basercms
(Composer)
May 14, 2022
Elefant CMS Code Execution Vulnerability
Critical
CVE-2018-16974
was published
for
elefant/cms
(Composer)
May 14, 2022
FineUploader php-traditional-server unauthenticated arbitrary file upload vulnerability
Critical
CVE-2018-9209
was published
for
fineuploader/php-traditional-server
(Composer)
May 14, 2022
Symfony Path Disclosure
Moderate
CVE-2018-19789
was published
for
symfony/form
(Composer)
May 14, 2022
Drupal Settings Tray access bypass
Moderate
CVE-2017-6931
was published
for
drupal/core
(Composer)
May 13, 2022
October CMS PHP Code Execution
High
CVE-2017-1000119
was published
for
october/cms
(Composer)
May 13, 2022
October CMS File Upload Vulnerability
Critical
CVE-2017-1000194
was published
for
october/october
(Composer)
May 13, 2022
Craft CMS PHP Code Injection Vulnerability
High
CVE-2018-3814
was published
for
craftcms/cms
(Composer)
May 13, 2022
RCE in baserCMS before 4.1.4
High
CVE-2018-18942
was published
for
baserproject/basercms
(Composer)
May 13, 2022
Bolt Unrestricted Upload of File with Dangerous Type
High
CVE-2019-9185
was published
for
bolt/bolt
(Composer)
May 13, 2022
Subrion CMS RCE Vulnerability
High
CVE-2018-19422
was published
for
intelliants/subrion
(Composer)
May 13, 2022
Unrestricted Upload of File with Dangerous Type in yetiforce-crm
Moderate
CVE-2022-1411
was published
for
yetiforce/yetiforce-crm
(Composer)
May 6, 2022
TYPO3 Unrestricted File Upload vulnerability
Moderate
CVE-2008-2717
was published
for
typo3/cms-core
(Composer)
May 1, 2022
TYPO3 Arbitrary Code Execution vulnerability on the backend
High
CVE-2010-3663
was published
for
typo3/cms-backend
(Composer)
Apr 21, 2022
ProTip!
Advisories are also available from the
GraphQL API