GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,228
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
23,684 advisories
Filter by severity
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2025-10294
was published
Oct 15, 2025
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via...
Critical
Unreviewed
CVE-2025-9967
was published
Oct 15, 2025
The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2025-10041
was published
Oct 15, 2025
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious...
Critical
Unreviewed
CVE-2018-25117
was published
Oct 15, 2025
DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in...
Critical
Unreviewed
CVE-2017-20204
was published
Oct 15, 2025
Valve's Source SDK (source-sdk-2013)'s ragdoll model parsing logic contains a stack-based buffer...
Critical
Unreviewed
CVE-2017-20205
was published
Oct 15, 2025
The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human...
Critical
Unreviewed
CVE-2011-10033
was published
Oct 15, 2025
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7311
was published
Oct 15, 2025
SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet...
Critical
Unreviewed
CVE-2023-7305
was published
Oct 15, 2025
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7304
was published
Oct 15, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS)...
Critical
Unreviewed
CVE-2025-49553
was published
Oct 15, 2025
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized...
Critical
Unreviewed
CVE-2025-59287
was published
Oct 14, 2025
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2025-49708
was published
Oct 14, 2025
A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain...
Critical
Unreviewed
CVE-2025-11548
was published
Oct 14, 2025
Multiple Broken Authentication security issues exist in the affected product. The security issues...
Critical
Unreviewed
CVE-2025-7328
was published
Oct 14, 2025
When switching between Android apps using the card carousel Firefox shows a black screen as its...
Critical
Unreviewed
CVE-2025-11717
was published
Oct 14, 2025
A compromised web process was able to trigger out of bounds reads and writes in a more privileged...
Critical
Unreviewed
CVE-2025-11709
was published
Oct 14, 2025
A compromised web process using malicious IPC messages could have caused the privileged browser...
Critical
Unreviewed
CVE-2025-11710
was published
Oct 14, 2025
Use-after-free in MediaTrackGraphImpl::GetInstance() This vulnerability affects Firefox < 144,...
Critical
Unreviewed
CVE-2025-11708
was published
Oct 14, 2025
Starting in Firefox 143, the use of the native messaging API by web extensions on Windows could...
Critical
Unreviewed
CVE-2025-11719
was published
Oct 14, 2025
Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory...
Critical
Unreviewed
CVE-2025-11721
was published
Oct 14, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-10610
was published
Oct 14, 2025
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions <...
Critical
Unreviewed
CVE-2025-40771
was published
Oct 14, 2025
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 <...
Critical
Unreviewed
CVE-2025-40765
was published
Oct 14, 2025
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An...
Critical
Unreviewed
CVE-2025-46581
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API