GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
2,470 advisories
Filter by severity
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 ...
High
Unreviewed
CVE-2021-43970
was published
Mar 11, 2022
Unrestricted Upload of File with Dangerous Type in Microweber
Moderate
CVE-2022-0921
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Unrestricted Upload of File with Dangerous Type in microweber
Moderate
CVE-2022-0912
was published
for
microweber/microweber
(Composer)
Mar 12, 2022
Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius
Moderate
CVE-2022-24749
was published
for
Sylius/Sylius
(Composer)
Mar 14, 2022
Cross-site Scripting in showdoc/showdoc
Critical
CVE-2022-0960
was published
for
showdoc/showdoc
(Composer)
Mar 15, 2022
Unrestricted Upload of File with Dangerous Type in Zenario CMS
Critical
CVE-2021-42171
was published
for
tribalsystems/zenario
(Composer)
Mar 15, 2022
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow...
Critical
Unreviewed
CVE-2021-25003
was published
Mar 15, 2022
With administrator or admin privileges the application can be tricked into overwriting files in...
High
Unreviewed
CVE-2022-24387
was published
Mar 15, 2022
The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to...
Critical
Unreviewed
CVE-2022-25495
was published
Mar 16, 2022
Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin...
Critical
Unreviewed
CVE-2022-25487
was published
Mar 16, 2022
File Upload Restriction Bypass leading to Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0951
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
Cross-site Scripting in ShowDoc
Moderate
CVE-2022-0950
was published
for
showdoc/showdoc
(Composer)
Mar 16, 2022
pgAdmin 4 Path Traversal vulnerability
Moderate
CVE-2022-0959
was published
for
pgadmin4
(pip)
Mar 17, 2022
The Spatie media-library-pro library through 1.17.10 and 2.x through 2.1.6 for Laravel allows...
Critical
Unreviewed
CVE-2021-45040
was published
Mar 18, 2022
Nonce token leak vulnerability leading to arbitrary file upload, theme deletion, plugin settings...
High
Unreviewed
CVE-2022-25602
was published
Mar 19, 2022
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action...
High
Unreviewed
CVE-2022-26965
was published
Mar 19, 2022
An attacker can upload or transfer files of dangerous types to the OpenDocMan 1.4.4 portal via...
Critical
Unreviewed
CVE-2021-45834
was published
Mar 19, 2022
The Online Admission System 1.0 allows an unauthenticated attacker to upload or transfer files of...
Critical
Unreviewed
CVE-2021-45835
was published
Mar 19, 2022
Classcms v2.5 and below contains an arbitrary file upload via the component \class\classupload....
High
Unreviewed
CVE-2022-25581
was published
Mar 20, 2022
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
High
Unreviewed
CVE-2022-23346
was published
Mar 22, 2022
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is...
High
Unreviewed
CVE-2022-0687
was published
Mar 22, 2022
DWSurvey v3.2.0 was discovered to contain an arbitrary file write vulnerability via the component...
Critical
Unreviewed
CVE-2021-39384
was published
Mar 22, 2022
The PluginsUpload function in application/service/PluginsAdminService.php of ShopXO v1.9.0...
High
Unreviewed
CVE-2020-26008
was published
Mar 22, 2022
An arbitrary file upload vulnerability in the upload payment plugin of ShopXO v1.9.0 allows...
High
Unreviewed
CVE-2020-26007
was published
Mar 22, 2022
Unrestricted Upload of File with Dangerous Type in ShowDoc
High
CVE-2022-1034
was published
for
showdoc/showdoc
(Composer)
Mar 23, 2022
ProTip!
Advisories are also available from the
GraphQL API