GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,757
Maven
5,000+
npm
4,363
NuGet
766
pip
4,128
Pub
12
RubyGems
961
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
12,887 advisories
Filter by severity
Moodle does not set the RISK_XSS bit for graders
Low
CVE-2015-0216
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering...
Low
Unreviewed
CVE-2015-3177
was published
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2015-3178
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2015-2273
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not set the RISK_XSS bit for graders
Low
CVE-2015-3174
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to bypass intended login restrictions
Low
CVE-2015-3179
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to upload files containing JavaScript
Low
CVE-2014-7835
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2015-0212
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle multiple cross-site scripting (XSS) vulnerabilities
Low
CVE-2014-3551
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2014-7830
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Low
CVE-2014-3544
was published
for
moodle/moodle
(Composer)
May 13, 2022
Cisco Unified Communications Manager (CUCM) 7.1(x) through 9.1(2) and the IM & Presence Service...
Low
Unreviewed
CVE-2013-4869
was published
May 13, 2022
Quick Emulator (Qemu) built with the Virtio GPU Device emulator support is vulnerable to an...
Low
Unreviewed
CVE-2016-9908
was published
May 13, 2022
MantisBT before 1.2.11 does not check the delete_attachments_threshold permission when...
Low
Unreviewed
CVE-2012-2692
was published
May 13, 2022
Cross-site scripting (XSS) vulnerability in helper_api.php in MantisBT 1.1.0a1 through 1.2.x...
Low
Unreviewed
CVE-2014-9269
was published
May 13, 2022
Cross-site scripting (XSS) vulnerability in account_sponsor_page.php in MantisBT 1.0.0 through 1...
Low
Unreviewed
CVE-2013-4460
was published
May 13, 2022
The SOAP API in MantisBT before 1.2.9 does not properly enforce the...
Low
Unreviewed
CVE-2012-1120
was published
May 13, 2022
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap...
Low
Unreviewed
CVE-2014-5353
was published
May 13, 2022
Microsoft Internet Information Services (IIS) 7.5 uses weak permissions for the Operational log,...
Low
Unreviewed
CVE-2012-2531
was published
May 13, 2022
Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login,...
Low
Unreviewed
CVE-2011-1007
was published
May 13, 2022
The commandline package update tool zypper writes HTTP proxy credentials into its logfile,...
Low
Unreviewed
CVE-2017-9271
was published
May 13, 2022
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown...
Low
Unreviewed
CVE-2016-9085
was published
May 13, 2022
ActiveMQ's OpenWire protocol exposes certain system details as plain text
Low
CVE-2017-15709
was published
for
org.apache.activemq:activemq-openwire-generator
(Maven)
May 13, 2022
OpenStack Horizon Cross-site scripting (XSS) vulnerability
Low
CVE-2014-3474
was published
for
horizon
(pip)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API