GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,618
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,042
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            44 advisories
        Filter by severity
        
      
      
    
                    
                      elFinder before 2.1.59 contains multiple vulnerabilities leading to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2021-32682
                      
                      was published
                        for
                        
                          studio-42/elfinder
                        
                        (Composer)
                      Jun 16, 2021 
                    
                  
                    
                      Command injection in mail agent settings
                    
                      
  High
                    
                
                      
                        CVE-2021-37708
                      
                      was published
                        for
                        
                          shopware/core
                        
                        (Composer)
                      Aug 30, 2021 
                    
                  
                    
                      OS Command injection in Bolt
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-28925
                      
                      was published
                        for
                        
                          bolt/bolt
                        
                        (Composer)
                      May 6, 2021 
                    
                  
                    
                      Command Injection in Centreon
                    
                      
  High
                    
                
                      
                        CVE-2020-13252
                      
                      was published
                        for
                        
                          centreon/centreon
                        
                        (Composer)
                      Jun 22, 2021 
                    
                  
                    
                      OS Command Injection in Centreon
                    
                      
  High
                    
                
                      
                        CVE-2020-22345
                      
                      was published
                        for
                        
                          centreon/centreon
                        
                        (Composer)
                      Sep 2, 2021 
                    
                  
                    
                      OS Command Injection Vulnerability and Potential Zip Slip Vulnerability in baserCMS
                    
                      
  Critical
                    
                
                      
                        CVE-2021-41243
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Dec 1, 2021 
                    
                  
                    
                      OS Command Injection in Laravel Framework
                    
                      
  High
                    
                
                      
                        CVE-2020-19316
                      
                      was published
                        for
                        
                          laravel/framework
                        
                        (Composer)
                      Jan 6, 2022 
                    
                  
                    
                      OS Command Injection in Microweber
                    
                      
  High
                    
                
                      
                        CVE-2022-0557
                      
                      was published
                        for
                        
                          microweber/microweber
                        
                        (Composer)
                      Feb 12, 2022 
                    
                  
                    
                      OS Command Injection in baserCMS
                    
                      
  High
                    
                
                      
                        CVE-2021-20682
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Jun 8, 2021 
                    
                  
                    
                      Zen Cart vulnerable to authenticated remote code execution
                    
                      
  High
                    
                
                      
                        CVE-2021-3291
                      
                      was published
                        for
                        
                          zencart/zencart
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      OS Command Injection in baserCMS
                    
                      
  High
                    
                
                      
                        CVE-2018-0569
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      May 14, 2022 
                    
                  
                    
                      Remote code injection in wwbn/avideo
                    
                      
  High
                    
                
                      
                        CVE-2023-30854
                      
                      was published
                        for
                        
                          wwbn/avideo
                        
                        (Composer)
                      Apr 27, 2023 
                    
                  
                    
                      Duplicate Advisory: AVideo contains Command injection when embedding a video link
                    
                      
  Critical
                    
                
                      
                        GHSA-wj6r-53f5-q789
                      
                      was published
                        for
                        
                          wwbn/avideo
                        
                        (Composer)
                      Apr 25, 2023 
                        •
                        
                          withdrawn
                    
                  
                    
                      Magento OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2021-21018
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      Magento OS command injection via the customer attribute save controller
                    
                      
  High
                    
                
                      
                        CVE-2021-21015
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      Indexed Search Engine for TYPO3 Command Execution via Metacharacter Injection
                    
                      
  High
                    
                
                      
                        CVE-2009-0258
                      
                      was published
                        for
                        
                          typo3/cms
                        
                        (Composer)
                      May 2, 2022 
                    
                  
                    
                      Reflected XSS in SilverStripe
                    
                      
  Moderate
                    
                
                      
                        CVE-2019-19325
                      
                      was published
                        for
                        
                          silverstripe/framework
                        
                        (Composer)
                      Feb 24, 2020 
                    
                  
                    
                      elFinder command injection vulnerability in the PHP connector
                    
                      
  Critical
                    
                
                      
                        CVE-2019-9194
                      
                      was published
                        for
                        
                          studio-42/elfinder
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Magento 2 Community Edition RCE Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2019-8159
                      
                      was published
                        for
                        
                          magento/community-edition
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      baserCMS OS command injection vulnerability in Installer
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-51450
                      
                      was published
                        for
                        
                          baserproject/basercms
                        
                        (Composer)
                      Feb 22, 2024 
                    
                  
                    
                      php-shellcommand command injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2019-10774
                      
                      was published
                        for
                        
                          mikehaertl/php-shellcommand
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      LibreNMS arbitrary OS commands execution
                    
                      
  Critical
                    
                
                      
                        CVE-2018-20434
                      
                      was published
                        for
                        
                          librenms/librenms
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      Froxlor arbitrary code execution via the database configuration options
                    
                      
  High
                    
                
                      
                        CVE-2020-10235
                      
                      was published
                        for
                        
                          froxlor/froxlor
                        
                        (Composer)
                      May 24, 2022 
                    
                  
                    
                      Akeneo PIM vulnerable to shell injection in the mass edition
                    
                      
  Critical
                    
                
                      
                        CVE-2017-1000009
                      
                      was published
                        for
                        
                          akeneo/pim-community-dev
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      Codiad Vulnerable to Shell Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2017-11366
                      
                      was published
                        for
                        
                          codiad/codiad
                        
                        (Composer)
                      May 13, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API