GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
58
GitHub Actions
50
Go
3,799
Maven
5,000+
npm
5,000+
NuGet
938
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,351
Swift
54
Unreviewed advisories
All unreviewed
5,000+
916 advisories
Filter by severity
Magento Remote code execution through catalog attribute sets
High
CVE-2019-8231
was published
for
magento/core
(Composer)
May 24, 2022
Magento Remote code execution through support/output path modification
High
CVE-2019-8230
was published
for
magento/core
(Composer)
May 24, 2022
Improper Control of Generation of Code in Jenkins Script Security Plugin
Critical
CVE-2019-10431
was published
for
org.jenkins-ci.plugins:script-security
(Maven)
May 24, 2022
Yii Framework Code Injection
High
CVE-2018-8074
was published
for
yiisoft/yii2-dev
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-7932
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition RCE
High
CVE-2019-7942
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-7903
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento 2 Community Edition Unsafe File Upload
High
CVE-2019-7871
was published
for
magento/community-edition
(Composer)
May 24, 2022
Moby Docker cp broken with debian containers
Critical
CVE-2019-14271
was published
for
github.com/docker/docker
(Go)
May 24, 2022
Dolibarr ERP and CRM Code Injection
High
CVE-2019-11201
was published
for
dolibarr/dolibarr
(Composer)
May 24, 2022
DOMPDF Remote Code Execution
High
CVE-2014-5013
was published
for
dompdf/dompdf
(Composer)
May 17, 2022
Cobbler is vulnerable to code injection
High
CVE-2010-2235
was published
for
cobbler
(pip)
May 17, 2022
DOMPDF Remote File Inclusion Vulnerability
High
CVE-2010-4879
was published
for
dompdf/dompdf
(Composer)
May 17, 2022
ImpressPages CMS eval injection vulnerability
High
CVE-2011-4932
was published
for
impresspages/impresspages
(Composer)
May 17, 2022
Improper Control of Generation of Code in Spring Security
Moderate
CVE-2011-2732
was published
for
org.springframework.security:spring-security-core
(Maven)
May 17, 2022
EGroupware Code Injection vulnerability
High
CVE-2010-3313
was published
for
egroupware/egroupware
(Composer)
May 17, 2022
graphite-web is vulnerable to Remote Code Execution via renderLocalView function
Critical
CVE-2013-5093
was published
for
graphite-web
(pip)
May 17, 2022
graphite-web is vulnerable to Remote Code Execution
Critical
CVE-2013-5942
was published
for
graphite-web
(pip)
May 17, 2022
phpMyAdmin Remote Code Execution
High
CVE-2013-3239
was published
for
phpmyadmin/phpmyadmin
(Composer)
May 17, 2022
Sup Code Injection vulnerability
Moderate
CVE-2013-4478
was published
for
sup
(RubyGems)
May 17, 2022
Code injection via property expansion in SoapUI
High
CVE-2014-1202
was published
for
com.smartbear.soapui:soapui
(Maven)
May 17, 2022
Apache Geronimo JMX Remoting functionality allows remote code execution in 3.x before v3.0.1
High
CVE-2013-1777
was published
for
org.apache.geronimo.framework:geronimo-jmx-remoting
(Maven)
May 17, 2022
Pimcore Vulnerable to PHP Object Injection Attacks
High
CVE-2014-2921
was published
for
pimcore/pimcore
(Composer)
May 17, 2022
TYPO3 vulnerable to remote authenticated arbitrary code execution
High
CVE-2013-4321
was published
for
typo3/cms
(Composer)
May 17, 2022
Yii PHP Framework arbitrary PHP scripts execution
High
CVE-2014-4672
was published
for
yiisoft/yii
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API