GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,464
Erlang
33
GitHub Actions
22
Go
2,163
Maven
5,000+
npm
3,821
NuGet
696
pip
3,502
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,464 advisories
Filter by severity
Flarum Vulnerable to Session Hijacking via Authoritative Subdomain Cookie Overwrite
Moderate
CVE-2025-27794
was published
for
flarum/core
(Composer)
Mar 12, 2025
Laravel has a File Validation Bypass
Moderate
CVE-2025-27515
was published
for
laravel/framework
(Composer)
Mar 5, 2025
laravel-crud-wizard-free has File Validation Bypass
Moderate
GHSA-3wgq-h4fr-cwg5
was published
for
macropay-solutions/laravel-crud-wizard-free
(Composer)
Mar 12, 2025
The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
High
CVE-2025-27773
was published
for
simplesamlphp/saml2
(Composer)
Mar 11, 2025
Pimcore Vulnerable to SQL Injection in getRelationFilterCondition
Moderate
CVE-2025-27617
was published
for
pimcore/pimcore
(Composer)
Mar 11, 2025
Froxlor has an HTML Injection Vulnerability
Moderate
GHSA-26xq-m8xw-6373
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Froxlor allows Multiple Accounts to Share the Same Email Address Leading to Potential Privilege Escalation or Account Takeover
Moderate
GHSA-7j6w-p859-464f
was published
for
froxlor/froxlor
(Composer)
Mar 11, 2025
Laravel framework susceptible to reflected cross-site scripting
Moderate
CVE-2024-13918
was published
for
laravel/framework
(Composer)
Mar 10, 2025
Concrete CMS affected by a stored XSS in Folder Function.The "Add Folder" functionality
Moderate
CVE-2025-0660
was published
for
concrete5/concrete5
(Composer)
Mar 10, 2025
Laravel framework susceptible to reflected cross-site scripting
Moderate
CVE-2024-13919
was published
for
laravel/framework
(Composer)
Mar 10, 2025
PocketMine-MP allows malicious client data to waste server resources due to lack of limits for explode()
Moderate
GHSA-g274-c6jj-h78p
was published
for
pocketmine/pocketmine-mp
(Composer)
Mar 10, 2025
Symfony vulnerable to command execution hijack on Windows with Process class
High
CVE-2024-51736
was published
for
symfony/process
(Composer)
Nov 6, 2024
phpseclib Infinite Loop vulnerability
High
CVE-2023-27560
was published
for
phpseclib/phpseclib
(Composer)
Mar 3, 2023
Moodle Session Fixation vulnerability
Critical
CVE-2021-36394
was published
for
moodle/moodle
(Composer)
Mar 6, 2023
PhpSpreadsheet allows bypassing of XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2025-23210
was published
for
phpoffice/phpexcel
(Composer)
Feb 3, 2025
XXE in PHPSpreadsheet's XLSX reader
High
CVE-2024-48917
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
High
CVE-2024-56365
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
High
CVE-2024-56366
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
High
CVE-2024-56408
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
High
CVE-2024-56409
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability in custom properties
Moderate
CVE-2024-56410
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet has a Cross-Site Scripting (XSS) vulnerability of the hyperlink base in the HTML page header
Moderate
CVE-2024-56411
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows bypass XSS sanitizer using the javascript protocol and special characters
Moderate
CVE-2024-56412
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
Cross-Site Scripting (XSS) vulnerability in generateNavigation() function in PhpSpreadsheet
Moderate
CVE-2025-22131
was published
for
phpoffice/phpexcel
(Composer)
Jan 21, 2025
XmlScanner bypass leads to XXE
High
CVE-2024-47873
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
ProTip!
Advisories are also available from the
GraphQL API