GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,697
Erlang
34
GitHub Actions
28
Go
2,289
Maven
5,000+
npm
3,936
NuGet
708
pip
3,706
Pub
12
RubyGems
919
Rust
959
Swift
38
Unreviewed advisories
All unreviewed
5,000+
985 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP...
Moderate
Unreviewed
CVE-2025-48119
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG...
Moderate
Unreviewed
CVE-2025-47562
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG Lite...
Moderate
Unreviewed
CVE-2025-48120
was published
May 16, 2025
Brandon
Rothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi
did not have a...
Moderate
Unreviewed
CVE-2023-5677
was published
Feb 5, 2024
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an...
Moderate
Unreviewed
CVE-2025-0134
was published
May 14, 2025
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-4022
was published
Apr 28, 2025
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0....
Moderate
Unreviewed
CVE-2025-3982
was published
Apr 27, 2025
OZI-Project/ozi-publish Code Injection vulnerability
Moderate
CVE-2025-47271
was published
for
OZI-Project/publish
(GitHub Actions)
May 12, 2025
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute...
Moderate
Unreviewed
CVE-2025-28201
was published
May 9, 2025
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-4208
was published
May 8, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member...
Moderate
Unreviewed
CVE-2025-47691
was published
May 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS...
Moderate
Unreviewed
CVE-2025-47481
was published
May 7, 2025
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a...
Moderate
Unreviewed
CVE-2024-13420
was published
May 2, 2025
Froxlor vulnerable to Code Injection
Moderate
CVE-2022-3721
was published
for
froxlor/froxlor
(Composer)
Nov 4, 2022
Flair allows arbitrary code execution
Moderate
CVE-2024-10073
was published
for
flair
(pip)
Oct 17, 2024
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue...
Moderate
Unreviewed
CVE-2025-3563
was published
Apr 14, 2025
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET...
Moderate
Unreviewed
CVE-2024-32499
was published
Apr 28, 2025
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Moderate
Unreviewed
CVE-2023-42404
was published
Apr 28, 2025
Pug allows JavaScript code execution if an application accepts untrusted input
Moderate
CVE-2024-36361
was published
for
pug
(npm)
May 24, 2024
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in...
Moderate
Unreviewed
CVE-2024-13812
was published
Apr 26, 2025
InternLM LMDeploy code injection vulnerability
Moderate
CVE-2025-3163
was published
for
lmdeploy
(pip)
Apr 3, 2025
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been...
Moderate
Unreviewed
CVE-2025-3164
was published
Apr 3, 2025
A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR...
Moderate
Unreviewed
CVE-2025-0618
was published
Apr 23, 2025
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
Moderate
Unreviewed
CVE-2025-3472
was published
Apr 22, 2025
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment...
Moderate
Unreviewed
CVE-2017-17649
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API