GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,133
Erlang
29
GitHub Actions
19
Go
1,940
Maven
5,000+
npm
3,677
NuGet
645
pip
3,295
Pub
11
RubyGems
877
Rust
830
Swift
35
Unreviewed advisories
All unreviewed
5,000+
98 advisories
Filter by severity
Moodle attackers to modify grade metadata
Moderate
CVE-2014-2572
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle creates a MoodleMobile web-service token with an infinite lifetime
Moderate
CVE-2014-0214
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2014-0126
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle multiple cross-site request forgery (CSRF) vulnerabilities
Moderate
CVE-2014-0213
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not check for the moodle/course:viewhiddencourses capability
Moderate
CVE-2014-0217
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly restrict file access
Moderate
CVE-2014-0216
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle's time-validation implementation allows bypassing intended restrictions
Moderate
CVE-2014-0127
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to bypass intended access restrictions
Moderate
CVE-2015-5342
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows bypass of intended access restrictions
Moderate
CVE-2014-0122
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly restrict access
Moderate
CVE-2014-0123
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle places a session key in a URL
Moderate
CVE-2014-0125
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive information
Moderate
CVE-2014-0124
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2013-7341
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to read SCORM contents
Moderate
CVE-2015-5341
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle mishandles group-based authorization checks
Moderate
CVE-2015-5268
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2015-5336
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle does not properly implement group-based access restrictions
Moderate
CVE-2015-5339
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Moderate
CVE-2015-5269
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle multiple cross-site scripting (XSS) vulnerabilities
Moderate
CVE-2015-3275
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site request forgery (CSRF) vulnerability
Moderate
CVE-2015-5335
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle cross-site scripting (XSS) vulnerability
Moderate
CVE-2015-3274
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to delete files
Moderate
CVE-2015-5265
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain manager privileges
Moderate
CVE-2015-5266
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to enter additional answer attempts
Moderate
CVE-2015-5264
was published
for
moodle/moodle
(Composer)
May 13, 2022
Moodle allows attackers to obtain sensitive course-structure information
Moderate
CVE-2015-3180
was published
for
moodle/moodle
(Composer)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API