GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,318
Erlang
31
GitHub Actions
21
Go
2,074
Maven
5,000+
npm
3,746
NuGet
674
pip
3,434
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
74 advisories
Filter by severity
Backdrop CMS Unrestricted File Upload vulnerability
High
CVE-2022-42092
was published
for
backdrop/backdrop
(Composer)
Oct 7, 2022
Drupal core arbitrary PHP code execution
High
CVE-2022-25277
was published
for
drupal/core
(Composer)
Aug 6, 2022
Feehi CMS arbitrary code execution via crafted PHP file
High
CVE-2022-34971
was published
for
feehi/cms
(Composer)
Jul 28, 2022
Unrestricted Upload of File with Dangerous Type in Elefant CMS
High
CVE-2017-20063
was published
for
elefant/cms
(Composer)
Jun 21, 2022
Unrestricted File Upload vulnerability in Firefly III
High
CVE-2021-3846
was published
for
grumpydictator/firefly-iii
(Composer)
May 24, 2022
Feehi CMS arbitrary file upload vulnerability
High
CVE-2020-22643
was published
for
feehi/cms
(Composer)
May 24, 2022
Dolibarr Unrestricted Upload of File with Dangerous Type
High
CVE-2020-14209
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
Silverstripe CMS malicious file upload enables script execution
High
CVE-2020-9309
was published
for
silverstripe/cms
(Composer)
May 24, 2022
Microweber allows Unrestricted File Upload
High
CVE-2020-13241
was published
for
microweber/microweber
(Composer)
May 24, 2022
SilverStripe Folders migrated from 3.x may be unsafe to upload to
High
CVE-2020-9280
was published
for
silverstripe/assets
(Composer)
May 24, 2022
FrozenNode Laravel-Administrator unrestricted file upload
High
CVE-2020-10963
was published
for
frozennode/administrator
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8114
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Information Disclosure via File upload functionality
High
CVE-2019-8093
was published
for
magento/community-edition
(Composer)
May 24, 2022
Pimcore Unrestricted Upload of File with Dangerous Type
High
CVE-2019-16318
was published
for
pimcore/pimcore
(Composer)
May 24, 2022
Magento 2 Community Unrestricted File Upload
High
CVE-2019-7930
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento Filter extension bypass via crafted store configuration keys
High
CVE-2019-7912
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Unsafe File Upload
High
CVE-2019-7861
was published
for
magento/community-edition
(Composer)
May 24, 2022
Arbitrary file upload in ShopXO
High
CVE-2021-41938
was published
for
shopxo/shopxo
(Composer)
May 20, 2022
jQuery File Upload Plugin Unrestricted file upload vulnerability
High
CVE-2014-8739
was published
for
blueimp/jquery-file-upload
(Composer)
May 17, 2022
Moodle Unrestricted file upload vulnerability
High
CVE-2016-9187
was published
for
moodle/moodle
(Composer)
May 17, 2022
Dolibarr ERP and CRM Unsafe File Upload Vulnerability
High
CVE-2017-9840
was published
for
dolibarr/dolibarr
(Composer)
May 17, 2022
TYPO3 Arbitrary Code Execution
High
CVE-2017-14251
was published
for
typo3/cms
(Composer)
May 17, 2022
TeamPass arbitrary file upload vulnerability
High
CVE-2017-15054
was published
for
nilsteampassnet/teampass
(Composer)
May 17, 2022
October CMS PHP Code Execution
High
CVE-2017-1000119
was published
for
october/cms
(Composer)
May 13, 2022
Craft CMS PHP Code Injection Vulnerability
High
CVE-2018-3814
was published
for
craftcms/cms
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API