GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
130,659 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site...
Moderate
Unreviewed
CVE-2025-64368
was published
Oct 31, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64354
was published
Oct 31, 2025
Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet...
Moderate
Unreviewed
CVE-2025-64356
was published
Oct 31, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced...
Moderate
Unreviewed
CVE-2025-64357
was published
Oct 31, 2025
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons...
Moderate
Unreviewed
CVE-2025-64358
was published
Oct 31, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-64361
was published
Oct 31, 2025
Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions...
Moderate
Unreviewed
CVE-2025-11602
was published
Oct 31, 2025
A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances...
Moderate
Unreviewed
CVE-2025-40603
was published
Oct 31, 2025
Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO...
Moderate
Unreviewed
CVE-2025-64351
was published
Oct 31, 2025
The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a...
Moderate
Unreviewed
CVE-2025-12041
was published
Oct 31, 2025
The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less...
Moderate
Unreviewed
CVE-2025-8383
was published
Oct 31, 2025
The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and...
Moderate
Unreviewed
CVE-2025-8385
was published
Oct 31, 2025
Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to...
Moderate
Unreviewed
CVE-2025-30191
was published
Oct 31, 2025
The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for...
Moderate
Unreviewed
CVE-2025-12094
was published
Oct 31, 2025
The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a...
Moderate
Unreviewed
CVE-2025-12175
was published
Oct 31, 2025
The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission...
Moderate
Unreviewed
CVE-2025-11191
was published
Oct 31, 2025
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and...
Moderate
Unreviewed
CVE-2025-58152
was published
Oct 31, 2025
The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ...
Moderate
Unreviewed
CVE-2025-11806
was published
Oct 31, 2025
The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant...
Moderate
Unreviewed
CVE-2025-11975
was published
Oct 31, 2025
In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the ...
Moderate
Unreviewed
CVE-2025-48980
was published
Oct 31, 2025
LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded...
Moderate
Unreviewed
CVE-2025-8849
was published
Oct 31, 2025
A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver...
Moderate
Unreviewed
CVE-2025-27208
was published
Oct 31, 2025
Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import...
Moderate
Unreviewed
CVE-2025-34270
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets...
Moderate
Unreviewed
CVE-2025-34135
was published
Oct 31, 2025
Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS)...
Moderate
Unreviewed
CVE-2025-34278
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API