GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,633
Erlang
34
GitHub Actions
25
Go
2,239
Maven
5,000+
npm
3,900
NuGet
701
pip
3,667
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
274,994 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-22664
was published
Feb 4, 2025
A vulnerability was found in itsourcecode Tailoring Management System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-0950
was published
Feb 1, 2025
The Login Manager – Design Login Page, View Login Activity, Limit Login Attempts plugin for...
Moderate
Unreviewed
CVE-2025-2613
was published
Apr 18, 2025
The Avatar plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file...
High
Unreviewed
CVE-2025-3520
was published
Apr 18, 2025
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-13650
was published
Apr 18, 2025
A Stored cross-site scripting (XSS)
vulnerability in upnp page of the web Interface in TP-Link...
High
Unreviewed
CVE-2025-25427
was published
Apr 18, 2025
Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU...
Unknown
Unreviewed
CVE-2025-0467
was published
Apr 18, 2025
HCL MyXalytics is affected by a failure to restrict URL access vulnerability. Unauthenticated...
Low
Unreviewed
CVE-2024-42178
was published
Apr 18, 2025
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker...
Unknown
Unreviewed
CVE-2025-29456
was published
Apr 18, 2025
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a...
Unknown
Unreviewed
CVE-2025-29457
was published
Apr 18, 2025
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change...
Unknown
Unreviewed
CVE-2025-29458
was published
Apr 18, 2025
An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the ...
Unknown
Unreviewed
CVE-2025-29461
was published
Apr 18, 2025
An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-3246
was published
Apr 18, 2025
A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a...
Moderate
Unreviewed
CVE-2025-3124
was published
Apr 18, 2025
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add...
Unknown
Unreviewed
CVE-2025-29460
was published
Apr 18, 2025
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail...
Unknown
Unreviewed
CVE-2025-29459
was published
Apr 18, 2025
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that...
High
Unreviewed
CVE-2025-3509
was published
Apr 18, 2025
An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker...
Unknown
Unreviewed
CVE-2025-29453
was published
Apr 18, 2025
cycle-import-check vulnerable to Command Injection
Critical
CVE-2022-24377
was published
for
cycle-import-check
(npm)
Dec 14, 2022
Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)
High
CVE-2024-46987
was published
for
camaleon_cms
(RubyGems)
Sep 18, 2024
Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)
High
CVE-2024-46986
was published
for
camaleon_cms
(RubyGems)
Sep 18, 2024
juzawebCMS Incorrect Access Control vulnerability
Moderate
CVE-2023-46906
was published
for
juzaweb/cms
(Composer)
Jan 9, 2024
A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions...
Moderate
Unreviewed
CVE-2025-29722
was published
Apr 17, 2025
In the Linux kernel, the following vulnerability has been resolved:
can: peak_usb: fix use after...
High
Unreviewed
CVE-2021-47670
was published
Apr 17, 2025
The Ultimate Dashboard WordPress plugin before 3.8.6 does not sanitise and escape some of its...
Low
Unreviewed
CVE-2025-1523
was published
Apr 17, 2025
ProTip!
Advisories are also available from the
GraphQL API