GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,688
Erlang
34
GitHub Actions
26
Go
2,274
Maven
5,000+
npm
3,930
NuGet
706
pip
3,696
Pub
12
RubyGems
919
Rust
955
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
3,742 advisories
Filter by severity
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a...
Critical
Unreviewed
CVE-2025-29509
was published
May 9, 2025
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management...
Critical
Unreviewed
CVE-2025-46191
was published
May 9, 2025
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Critical
Unreviewed
CVE-2025-28203
was published
May 9, 2025
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute...
Moderate
Unreviewed
CVE-2025-28201
was published
May 9, 2025
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-4208
was published
May 8, 2025
The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13793
was published
May 8, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member...
Moderate
Unreviewed
CVE-2025-47691
was published
May 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS...
Moderate
Unreviewed
CVE-2025-47481
was published
May 7, 2025
The LayoutBoxx plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
High
Unreviewed
CVE-2025-2802
was published
May 6, 2025
SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the...
Critical
Unreviewed
CVE-2025-44071
was published
May 6, 2025
The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable...
High
Unreviewed
CVE-2024-13738
was published
May 3, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics...
High
Unreviewed
CVE-2025-2421
was published
May 2, 2025
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a...
Moderate
Unreviewed
CVE-2024-13420
was published
May 2, 2025
An issue in phpgurukul Online Banquet Booking System V1.2 allows an attacker to execute arbitrary...
Critical
Unreviewed
CVE-2025-45947
was published
Apr 28, 2025
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Moderate
Unreviewed
CVE-2023-42404
was published
Apr 28, 2025
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET...
Moderate
Unreviewed
CVE-2024-32499
was published
Apr 28, 2025
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0....
Moderate
Unreviewed
CVE-2025-3982
was published
Apr 27, 2025
There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE...
High
Unreviewed
CVE-2025-46579
was published
Apr 27, 2025
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in...
Moderate
Unreviewed
CVE-2024-13812
was published
Apr 26, 2025
The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to...
High
Unreviewed
CVE-2025-3491
was published
Apr 26, 2025
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in...
High
Unreviewed
CVE-2024-13808
was published
Apr 26, 2025
The The Create custom forms for WordPress with a smart form plugin for smart businesses plugin...
High
Unreviewed
CVE-2025-2801
was published
Apr 26, 2025
The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code...
High
Unreviewed
CVE-2025-3776
was published
Apr 24, 2025
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user...
High
Unreviewed
CVE-2025-1976
was published
Apr 24, 2025
A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR...
Moderate
Unreviewed
CVE-2025-0618
was published
Apr 23, 2025
ProTip!
Advisories are also available from the
GraphQL API