GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,228
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
23,678 advisories
Filter by severity
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all...
Critical
Unreviewed
CVE-2025-10294
was published
Oct 15, 2025
The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via...
Critical
Unreviewed
CVE-2025-9967
was published
Oct 15, 2025
The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2025-10041
was published
Oct 15, 2025
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7311
was published
Oct 15, 2025
SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet...
Critical
Unreviewed
CVE-2023-7305
was published
Oct 15, 2025
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious...
Critical
Unreviewed
CVE-2018-25117
was published
Oct 15, 2025
DBLTek GoIP devices (models GoIP 1, 4, 8, 16, and 32) contain an undocumented vendor backdoor in...
Critical
Unreviewed
CVE-2017-20204
was published
Oct 15, 2025
Valve's Source SDK (source-sdk-2013)'s ragdoll model parsing logic contains a stack-based buffer...
Critical
Unreviewed
CVE-2017-20205
was published
Oct 15, 2025
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the ...
Critical
Unreviewed
CVE-2023-7304
was published
Oct 15, 2025
The WordPress plugin is-human <= v1.4.2 contains an eval injection vulnerability in /is-human...
Critical
Unreviewed
CVE-2011-10033
was published
Oct 15, 2025
Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS)...
Critical
Unreviewed
CVE-2025-49553
was published
Oct 15, 2025
Deserialization of untrusted data in Windows Server Update Service allows an unauthorized...
Critical
Unreviewed
CVE-2025-59287
was published
Oct 14, 2025
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate...
Critical
Unreviewed
CVE-2025-49708
was published
Oct 14, 2025
A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain...
Critical
Unreviewed
CVE-2025-11548
was published
Oct 14, 2025
Multiple Broken Authentication security issues exist in the affected product. The security issues...
Critical
Unreviewed
CVE-2025-7328
was published
Oct 14, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-10610
was published
Oct 14, 2025
A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions <...
Critical
Unreviewed
CVE-2025-40771
was published
Oct 14, 2025
A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 <...
Critical
Unreviewed
CVE-2025-40765
was published
Oct 14, 2025
ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An...
Critical
Unreviewed
CVE-2025-46581
was published
Oct 14, 2025
Due to missing verification of file type or content, SAP Supplier Relationship Management allows...
Critical
Unreviewed
CVE-2025-42910
was published
Oct 14, 2025
SAP Print Service (SAPSprint) performs insufficient validation of path information provided by...
Critical
Unreviewed
CVE-2025-42937
was published
Oct 14, 2025
Improper neutralization of special elements used in a template engine in Elastic Cloud Enterprise...
Critical
Unreviewed
CVE-2025-37729
was published
Oct 13, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-6919
was published
Oct 13, 2025
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform...
Critical
Unreviewed
CVE-2025-9976
was published
Oct 13, 2025
A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker...
Critical
Unreviewed
CVE-2025-9265
was published
Oct 13, 2025
ProTip!
Advisories are also available from the
GraphQL API