GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,681
Maven
5,000+
npm
4,309
NuGet
760
pip
4,083
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,044 advisories
Filter by severity
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2025-8878
was published
Aug 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS...
Moderate
Unreviewed
CVE-2025-7961
was published
Aug 15, 2025
The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all...
Moderate
Unreviewed
CVE-2025-8905
was published
Aug 15, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer...
Moderate
Unreviewed
CVE-2025-39483
was published
Aug 14, 2025
SAP NetWeaver Application Server ABAP has HTML injection vulnerability. Due to this, an attacker...
Moderate
Unreviewed
CVE-2025-42945
was published
Aug 12, 2025
Craft CMS has a theoretical bypass for CVE-2025-23209
Moderate
CVE-2025-54417
was published
for
craftcms/cms
(Composer)
Aug 8, 2025
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4...
Moderate
Unreviewed
CVE-2025-54940
was published
Aug 8, 2025
Pyload log Injection via API /json/add_package in add_name parameter
Moderate
GHSA-3wwm-hjv7-23r3
was published
for
pyload-ng
(pip)
Jul 30, 2025
SAP FICA ODN framework allows a high privileged user to inject value inside the local variable...
Moderate
Unreviewed
CVE-2025-42947
was published
Jul 23, 2025
A locally authenticated, privileged user can craft a malicious OpenSSL configuration file,...
Moderate
Unreviewed
CVE-2025-0664
was published
Jul 21, 2025
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of...
Moderate
Unreviewed
CVE-2025-46000
was published
Jul 18, 2025
A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown...
Moderate
Unreviewed
CVE-2024-12900
was published
Dec 23, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Directory...
Moderate
Unreviewed
CVE-2024-7650
was published
Jul 10, 2025
HashiCorp Vagrant has code injection vulnerability through default synced folders
Moderate
CVE-2025-34075
was published
for
vagrant
(RubyGems)
Jul 2, 2025
Stage.js DOM Clobbering vulnerabilty
Moderate
CVE-2024-53386
was published
for
stage-js
(npm)
Mar 3, 2025
PrismJS DOM Clobbering vulnerability
Moderate
CVE-2024-53382
was published
for
prismjs
(npm)
Mar 3, 2025
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary...
Moderate
Unreviewed
CVE-2025-24287
was published
Jun 19, 2025
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to...
Moderate
Unreviewed
CVE-2025-3841
was published
Apr 21, 2025
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate...
Moderate
Unreviewed
CVE-2023-51820
was published
Feb 2, 2024
A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-4218
was published
May 2, 2025
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is...
Moderate
Unreviewed
CVE-2025-6101
was published
Jun 16, 2025
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical....
Moderate
Unreviewed
CVE-2025-4866
was published
May 18, 2025
A vulnerability was found in DedeCMS 5.7.117. It has been classified as critical. Affected is an...
Moderate
Unreviewed
CVE-2025-5137
was published
May 25, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase...
Moderate
Unreviewed
CVE-2025-49250
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41362
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API