GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,472
Erlang
33
GitHub Actions
24
Go
2,187
Maven
5,000+
npm
3,841
NuGet
696
pip
3,609
Pub
12
RubyGems
911
Rust
910
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
248,565 advisories
Filter by severity
The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is...
High
Unreviewed
CVE-2024-2082
was published
May 2, 2024
The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2024-4374
was published
May 18, 2024
The Wow Skype Buttons WordPress plugin before 4.0.4 does not have CSRF checks in some bulk...
High
Unreviewed
CVE-2024-3474
was published
May 2, 2024
The EleForms – All In One Form Integration including DB for Elementor plugin for WordPress is...
Moderate
Unreviewed
CVE-2024-2043
was published
May 2, 2024
In the Linux kernel, the following vulnerability has been resolved:
bnxt: prevent skb UAF after...
High
Unreviewed
CVE-2022-48637
was published
Apr 28, 2024
The Easy PayPal & Stripe Buy Now Button plugin for WordPress is vulnerable to Cross-Site Request...
Moderate
Unreviewed
CVE-2024-1719
was published
Feb 28, 2024
The WordPress Download Manager WordPress plugin before 3.2.22 does not sanitise and escape...
Moderate
Unreviewed
CVE-2021-24969
was published
Dec 28, 2021
Authenticated File Upload in WordPress Download Manager <= 3.1.24 allows authenticated (Author+)...
High
Unreviewed
CVE-2021-34639
was published
May 24, 2022
Authenticated Directory Traversal in WordPress Download Manager <= 3.1.24 allows authenticated ...
Moderate
Unreviewed
CVE-2021-34638
was published
May 24, 2022
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote...
Moderate
Unreviewed
CVE-2017-2217
was published
May 13, 2022
An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that...
Critical
Unreviewed
CVE-2025-30122
was published
Mar 18, 2025
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials...
Critical
Unreviewed
CVE-2025-30115
was published
Mar 18, 2025
An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials...
Critical
Unreviewed
CVE-2025-30113
was published
Mar 18, 2025
An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as...
Critical
Unreviewed
CVE-2025-30132
was published
Mar 18, 2025
A logic issue was addressed with improved file handling. This issue is fixed in visionOS 2.2,...
High
Unreviewed
CVE-2024-54525
was published
Mar 17, 2025
An issue was discovered in GL-INet Beryl AX GL-MT3000 v4.7.0. Attackers are able to download...
High
Unreviewed
CVE-2025-25685
was published
Mar 17, 2025
Sunlogin Sunflower Simplified (aka Sunflower Simple and Personal) 1.0.1.43315 is vulnerable to a...
Critical
Unreviewed
CVE-2022-48323
was published
Feb 13, 2023
SUSHIRO App for Android outputs sensitive information to the log file, which may result in an...
High
Unreviewed
CVE-2023-22362
was published
Feb 13, 2023
LibTIFF 4.4.0 has an out-of-bounds write in tiffcrop in tools/tiffcrop.c:3609, allowing attackers...
Moderate
Unreviewed
CVE-2023-0804
was published
Feb 14, 2023
ConnectWise Control before 22.9.10032 (formerly known as ScreenConnect) fails to validate user...
High
Unreviewed
CVE-2023-25719
was published
Feb 13, 2023
In the Linux kernel, the following vulnerability has been resolved:
wifi: wfx: fix memory leak...
Moderate
Unreviewed
CVE-2024-26896
was published
Apr 17, 2024
In the Linux kernel, the following vulnerability has been resolved:
tty: tty_buffer: Fix the...
Moderate
Unreviewed
CVE-2021-47185
was published
Apr 10, 2024
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2. An app...
Moderate
Unreviewed
CVE-2024-54565
was published
Mar 17, 2025
In the Linux kernel, the following vulnerability has been resolved:
geneve: make sure to pull...
Moderate
Unreviewed
CVE-2024-26857
was published
Apr 17, 2024
An issue was discovered in Shopxian CMS 3.0.0. There is a CSRF vulnerability that can delete the...
Moderate
Unreviewed
CVE-2022-38329
was published
Sep 14, 2022
ProTip!
Advisories are also available from the
GraphQL API