GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,166
Maven
5,000+
npm
3,830
NuGet
696
pip
3,507
Pub
12
RubyGems
909
Rust
904
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,198 advisories
Filter by severity
Formwork improperly validates input of User role preventing site and panel availability
High
GHSA-c85w-x26q-ch87
was published
for
getformwork/formwork
(Composer)
Mar 1, 2025
The SimpleSAMLphp SAML2 library incorrectly verifies signatures for HTTP-Redirect binding
High
CVE-2025-27773
was published
for
simplesamlphp/saml2
(Composer)
Mar 11, 2025
Symfony vulnerable to command execution hijack on Windows with Process class
High
CVE-2024-51736
was published
for
symfony/process
(Composer)
Nov 6, 2024
phpseclib Infinite Loop vulnerability
High
CVE-2023-27560
was published
for
phpseclib/phpseclib
(Composer)
Mar 3, 2023
XXE in PHPSpreadsheet's XLSX reader
High
CVE-2024-48917
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
PhpSpreadsheet allows unauthorized Reflected XSS in the constructor of the Downloader class
High
CVE-2024-56365
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in the Accounting.php file
High
CVE-2024-56366
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in `Convert-Online.php` file
High
CVE-2024-56408
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
PhpSpreadsheet allows unauthorized Reflected XSS in Currency.php file
High
CVE-2024-56409
was published
for
phpoffice/phpexcel
(Composer)
Jan 3, 2025
XmlScanner bypass leads to XXE
High
CVE-2024-47873
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
XXE in PHPSpreadsheet's XLSX reader
High
CVE-2024-45293
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
PhpSpreadsheet allows absolute path traversal and Server-Side Request Forgery when opening XLSX file
High
CVE-2024-45290
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
XXE in PHPSpreadsheet encoding is returned
High
CVE-2024-45048
was published
for
phpoffice/phpexcel
(Composer)
Aug 29, 2024
XXE in PHPSpreadsheet due to encoding issue
High
CVE-2018-19277
was published
for
phpoffice/phpexcel
(Composer)
Nov 20, 2019
XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue
High
CVE-2019-12331
was published
for
phpoffice/phpexcel
(Composer)
Nov 20, 2019
Magento Open Source allows Improper Input Validation
High
CVE-2024-20758
was published
for
magento/community-edition
(Composer)
Apr 10, 2024
Magento Open Source allows OS Command Injection
High
CVE-2024-20720
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
Magento Open Source allows Cross-Site Scripting (XSS)
High
CVE-2024-20719
was published
for
magento/community-edition
(Composer)
Feb 15, 2024
Magento Open Source allows Improper Neutralization of Special Elements Used
High
CVE-2023-38208
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows Improper Neutralization of Special Elements Used
High
CVE-2023-29297
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
Magento Open Source allows Stored Cross-Site Scripting (Stored XSS)
High
CVE-2022-35698
was published
for
magento/community-edition
(Composer)
Oct 15, 2022
Mautic vulnerable to Improper Access Control in UI upgrade process
High
CVE-2022-25768
was published
for
mautic/core
(Composer)
Sep 18, 2024
Magento stored Cross-Site Scripting (XSS) vulnerability
High
CVE-2025-24438
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
Magento Stored Cross-Site Scripting (XSS) Vulnerability
High
CVE-2025-24417
was published
for
magento/community-edition
(Composer)
Feb 11, 2025
ProTip!
Advisories are also available from the
GraphQL API