GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,638
Maven
5,000+
npm
4,263
NuGet
760
pip
4,058
Pub
12
RubyGems
956
Rust
1,056
Swift
45
Unreviewed advisories
All unreviewed
5,000+
6,773 advisories
Filter by severity
Moodle Information Disclosure
Moderate
CVE-2017-7531
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle sensitive information disclosure
Moderate
CVE-2015-5340
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive course-structure information
Moderate
CVE-2015-3180
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers obtain full-name information
Moderate
CVE-2015-3176
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive personal-contact and unread-message-count information
Moderate
CVE-2015-2266
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attacks to obtain sensitive information
Moderate
CVE-2014-7848
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive information
Moderate
CVE-2015-0211
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive calendar-event information
Moderate
CVE-2015-0215
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle exposes hidden grades to students
Moderate
CVE-2014-7831
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive information
Moderate
CVE-2014-7833
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle sensitive information disclosure
Moderate
CVE-2016-5014
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows remote attackers to read arbitrary files
Moderate
CVE-2014-3542
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to discover hidden course names
Moderate
CVE-2016-2154
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle sensitive information disclosure
Moderate
CVE-2016-0724
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle provides calendar-event data without considering whether an activity is hidden
Moderate
CVE-2016-2156
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive category-detail information
Moderate
CVE-2016-2158
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle sensitive information disclosure
Moderate
CVE-2016-3732
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to discover student e-mail addresses
Moderate
CVE-2016-2151
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to...
Moderate
Unreviewed
CVE-2016-3731
was published
May 13, 2022
The web console login form in ovirt-engine before version 4.2.3 returned different errors for non...
Moderate
Unreviewed
CVE-2018-1073
was published
May 13, 2022
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
Moderate
CVE-2018-14642
was published
for
io.undertow:undertow-core
(Maven)
May 13, 2022
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a...
Moderate
Unreviewed
CVE-2018-15599
was published
May 13, 2022
The print_test_result function in admin/upgrade_unattended.php in MantisBT 1.1.0a3 through 1.2.x...
Moderate
Unreviewed
CVE-2014-9279
was published
May 13, 2022
The ASN1_TFLG_COMBINE implementation in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zh, 1.0.0...
Moderate
Unreviewed
CVE-2015-3195
was published
May 13, 2022
The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local...
Moderate
Unreviewed
CVE-2018-5953
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API