GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,703
NuGet
661
pip
3,329
Pub
11
RubyGems
884
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
33 advisories
Filter by severity
elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE
Critical
CVE-2021-32682
was published
for
studio-42/elfinder
(Composer)
Jun 16, 2021
Command injection in mail agent settings
High
CVE-2021-37708
was published
for
shopware/core
(Composer)
Aug 30, 2021
OS Command injection in Bolt
Moderate
CVE-2020-28925
was published
for
bolt/bolt
(Composer)
May 6, 2021
Command Injection in Centreon
High
CVE-2020-13252
was published
for
centreon/centreon
(Composer)
Jun 22, 2021
OS Command Injection in Centreon
High
CVE-2020-22345
was published
for
centreon/centreon
(Composer)
Sep 2, 2021
OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS
Critical
CVE-2021-41243
was published
for
baserproject/basercms
(Composer)
Dec 1, 2021
OS Command Injection in Laravel Framework
High
CVE-2020-19316
was published
for
laravel/framework
(Composer)
Jan 6, 2022
OS Command Injection in Microweber
High
CVE-2022-0557
was published
for
microweber/microweber
(Composer)
Feb 12, 2022
OS Command Injection in baserCMS
High
CVE-2021-20682
was published
for
baserproject/basercms
(Composer)
Jun 8, 2021
Zen Cart vulnerable to authenticated remote code execution
High
CVE-2021-3291
was published
for
zencart/zencart
(Composer)
May 24, 2022
OS Command Injection in baserCMS
High
CVE-2018-0569
was published
for
baserproject/basercms
(Composer)
May 14, 2022
Remote code injection in wwbn/avideo
High
CVE-2023-30854
was published
for
wwbn/avideo
(Composer)
Apr 27, 2023
Duplicate Advisory: AVideo contains Command injection when embedding a video link
Critical
GHSA-wj6r-53f5-q789
was published
for
wwbn/avideo
(Composer)
Apr 25, 2023
•
withdrawn
Magento OS Command Injection
Critical
CVE-2021-21018
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9583
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9578
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9576
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento OS command injection via the customer attribute save controller
High
CVE-2021-21015
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento OS command injection via the WebAPI
Critical
CVE-2021-21016
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento command injection vulnerability
Critical
CVE-2020-9582
was published
for
magento/community-edition
(Composer)
May 24, 2022
Indexed Search Engine for TYPO3 Command Execution via Metacharacter Injection
High
CVE-2009-0258
was published
for
typo3/cms
(Composer)
May 2, 2022
Reflected XSS in SilverStripe
Moderate
CVE-2019-19325
was published
for
silverstripe/framework
(Composer)
Feb 24, 2020
elFinder command injection vulnerability in the PHP connector
Critical
CVE-2019-9194
was published
for
studio-42/elfinder
(Composer)
May 13, 2022
Magento 2 Community Edition RCE Vulnerability
High
CVE-2019-8159
was published
for
magento/community-edition
(Composer)
May 24, 2022
baserCMS OS command injection vulnerability in Installer
Moderate
CVE-2023-51450
was published
for
baserproject/basercms
(Composer)
Feb 22, 2024
ProTip!
Advisories are also available from the
GraphQL API