GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
1,065 advisories
Filter by severity
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a...
Moderate
Unreviewed
CVE-2025-42895
was published
Nov 11, 2025
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-8483
was published
Oct 25, 2025
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept...
Moderate
Unreviewed
CVE-2025-8848
was published
Oct 22, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-11905
was published
Oct 17, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in...
Moderate
Unreviewed
CVE-2025-31365
was published
Oct 14, 2025
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript...
Moderate
Unreviewed
CVE-2025-42901
was published
Oct 14, 2025
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an...
Moderate
Unreviewed
CVE-2025-11344
was published
Oct 6, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce...
Moderate
Unreviewed
CVE-2025-60114
was published
Sep 26, 2025
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-10993
was published
Sep 26, 2025
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due...
Moderate
Unreviewed
CVE-2025-5717
was published
Sep 23, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Tareq Hasan WP User...
Moderate
Unreviewed
CVE-2025-58673
was published
Sep 22, 2025
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2025-9489
was published
Sep 9, 2025
SimStudioAI: A function in route.ts is vulnerable to Code Injection
Moderate
CVE-2025-10097
was published
for
simstudio
(npm)
Sep 8, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18...
Moderate
Unreviewed
CVE-2025-5101
was published
Aug 27, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone...
Moderate
Unreviewed
CVE-2025-54019
was published
Aug 20, 2025
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2025-8878
was published
Aug 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS...
Moderate
Unreviewed
CVE-2025-7961
was published
Aug 15, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE...
Moderate
Unreviewed
CVE-2025-54466
was published
Aug 15, 2025
The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all...
Moderate
Unreviewed
CVE-2025-8905
was published
Aug 15, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer...
Moderate
Unreviewed
CVE-2025-39483
was published
Aug 14, 2025
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker...
Moderate
Unreviewed
CVE-2025-42945
was published
Aug 12, 2025
ProTip!
Advisories are also available from the
GraphQL API