GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
4,334 advisories
Filter by severity
TYPO3 Cross-Site Request Forgery in Backend User Module
Moderate
CVE-2024-55894
was published
for
typo3/cms-beuser
(Composer)
Jan 14, 2025
TYPO3 Cross-Site Request Forgery in Log Module
Moderate
CVE-2024-55893
was published
for
typo3/cms-belog
(Composer)
Jan 14, 2025
TYPO3 Potential Open Redirect via Parsing Differences
Moderate
CVE-2024-55892
was published
for
typo3/cms-core
(Composer)
Jan 14, 2025
TYPO3 Information Disclosure via Exception Handling/Logger
Low
CVE-2024-55891
was published
for
typo3/cms-install
(Composer)
Jan 14, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33297
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33298
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Microweber Cross-site Scripting vulnerability
Moderate
CVE-2024-33299
was published
for
microweber/microweber
(Composer)
Jan 10, 2025
Drupal Open Social allows Functionality Misuse
Moderate
CVE-2024-13274
was published
for
goalgorilla/open_social
(Composer)
Jan 9, 2025
Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale
Moderate
CVE-2025-22145
was published
for
nesbot/carbon
(Composer)
Jan 8, 2025
PHP-Textile has persistent XSS vulnerability in image link handling
High
GHSA-95m2-chm4-mq7m
was published
for
netcarver/textile
(Composer)
Jan 7, 2025
Grav Cross-site Scripting vulnerability
Low
CVE-2024-35498
was published
for
getgrav/grav
(Composer)
Jan 6, 2025
REDAXO CMS Cross-site Scripting vulnerability
Low
CVE-2024-46209
was published
for
redaxo/source
(Composer)
Jan 6, 2025
Guzzle OAuth Subscriber has insufficient nonce entropy
Moderate
CVE-2025-21617
was published
for
guzzlehttp/oauth-subscriber
(Composer)
Jan 6, 2025
Extension:TabberNeue vulnerable to Cross-site Scripting
High
CVE-2025-21612
was published
for
starcitizentools/tabber-neue
(Composer)
Jan 6, 2025
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2024-56412
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Moderate
CVE-2024-56411
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
Moderate
CVE-2024-56410
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
High
CVE-2024-56409
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
High
CVE-2024-56366
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
High
CVE-2024-56365
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
High
CVE-2024-56408
was published
for
phpoffice/phpspreadsheet
(Composer)
Jan 3, 2025
phpMyFAQ Vulnerable to Stored HTML Injection at FAQ
Moderate
CVE-2024-56199
was published
for
phpmyfaq/phpmyfaq
(Composer)
Jan 2, 2025
LGSL has a reflected XSS at /lgsl_files/lgsl_list.php
Moderate
CVE-2024-56517
was published
for
tltneon/lgsl
(Composer)
Dec 30, 2024
TeamPass mail_me operation authorization issue
Moderate
CVE-2024-50702
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
TeamPass privileges issue
Critical
CVE-2024-50703
was published
for
nilsteampassnet/teampass
(Composer)
Dec 30, 2024
ProTip!
Advisories are also available from the
GraphQL API