GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,669
Erlang
34
GitHub Actions
26
Go
2,261
Maven
5,000+
npm
3,910
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,670 advisories
Filter by severity
Moodle allows IDOR when accessing the cohorts report
Moderate
CVE-2025-3647
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in Brickfield tool's analysis request action
Low
CVE-2025-3638
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has reflected Cross-site Scripting risk in policy tool
Moderate
CVE-2025-3643
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository
High
CVE-2025-3641
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has a CSRF risk in user tours manager that allows tour duplication
Low
CVE-2025-3635
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows IDOR in RSS block, which allows access to additional RSS feeds
Moderate
CVE-2025-3636
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's AJAX section delete does not respect course_can_delete_section()
Moderate
CVE-2025-3644
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle's mod_data edit/delete pages pass CSRF token in GET parameter
Low
CVE-2025-3637
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in messaging web service which allows access to some user details
Moderate
CVE-2025-3645
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an authenticated remote code execution risk in the Moodle LMS EQUELLA repository
High
CVE-2025-3642
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle has an IDOR in web service which allows users enrolled in a course to access some details of other users
Moderate
CVE-2025-3640
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle reveals student identities through assignment submissions search on anonymous submissions
Moderate
CVE-2025-3628
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle makes some user data available before completing second factor with MFA enabled
Moderate
CVE-2025-3627
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle self enrollment available before completing second factor with MFA enabled
Moderate
CVE-2025-3634
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle shows hidden grades to users without permission on some grade reports
Moderate
CVE-2025-32045
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Moodle allows unauthenticated REST API user data exposure
High
CVE-2025-32044
was published
for
moodle/moodle
(Composer)
Apr 25, 2025
Craft CMS Allows Remote Code Execution
Critical
CVE-2025-32432
was published
for
craftcms/cms
(Composer)
Apr 25, 2025
Laravel Starter Cross Site Scripting (XSS)
Moderate
CVE-2025-26159
was published
for
nasirkhan/laravel-starter
(Composer)
Apr 22, 2025
croogo Host header injection
Moderate
CVE-2024-29643
was published
for
croogo/croogo
(Composer)
Apr 21, 2025
PEAR HTTP_Request2 vulnerable to Cross-site Scripting
Moderate
CVE-2025-43717
was published
for
pear/http_request2
(Composer)
Apr 17, 2025
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
Formie has XSS vulnerability for email notification content for preview
Moderate
CVE-2025-32426
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Formie has XSS vulnerability for importing forms
Moderate
CVE-2025-32427
was published
for
verbb/formie
(Composer)
Apr 11, 2025
Yii does not prevent XSS in scenarios where fallback error renderer is used
Moderate
CVE-2025-32027
was published
for
yiisoft/yii
(Composer)
Apr 11, 2025
Silverstripe Framework user enumeration via timing attack on login and password reset forms
Moderate
GHSA-256q-hx8w-xcqx
was published
for
silverstripe/framework
(Composer)
Apr 10, 2025
ProTip!
Advisories are also available from the
GraphQL API