GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,679
Erlang
34
GitHub Actions
26
Go
2,268
Maven
5,000+
npm
3,923
NuGet
705
pip
3,686
Pub
12
RubyGems
916
Rust
944
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,680 advisories
Filter by severity
SQL injection in ADOdb PostgreSQL driver pg_insert_id() method
Critical
CVE-2025-46337
was published
for
adodb/adodb-php
(Composer)
May 1, 2025
ShowDoc unrestricted file upload vulnerability
Critical
CVE-2025-0520
was published
for
showdoc/showdoc
(Composer)
Apr 29, 2025
YesWiki Stored XSS Vulnerability in Comments
Low
CVE-2025-46346
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Remote Code Execution via Arbitrary PHP File Write and Execution
High
CVE-2025-46347
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Vulnerable to Unauthenticated Site Backup Creation and Download
Critical
CVE-2025-46348
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
YesWiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
High
CVE-2025-46349
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Authenticated Reflected Cross-site Scripting
Low
CVE-2025-46350
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46550
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Yeswiki Vulnerable to Unauthenticated Reflected Cross-site Scripting
Moderate
CVE-2025-46549
was published
for
yeswiki/yeswiki
(Composer)
Apr 29, 2025
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in user tours manager that allows tour duplication
Low
CVE-2025-3635
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
Low
CVE-2025-3637
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Moderate
CVE-2025-3636
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in Brickfield tool's analysis request action
Low
CVE-2025-3638
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
Moderate
CVE-2025-3640
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has reflected Cross-site Scripting risk in policy tool
Moderate
CVE-2025-3643
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
High
CVE-2025-3642
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
High
CVE-2025-3641
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle reveals student identities through assignment submissions search on anonymous submissions
Moderate
CVE-2025-3628
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle self enrollment available before completing second factor with MFA enabled
Moderate
CVE-2025-3634
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle shows hidden grades to users without permission on some grade reports
Moderate
CVE-2025-32045
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle makes some user data available before completing second factor with MFA enabled
Moderate
CVE-2025-3627
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
ProTip!
Advisories are also available from the
GraphQL API