GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
169 advisories
Filter by severity
The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to,...
Moderate
Unreviewed
CVE-2025-12747
was published
Nov 21, 2025
The Import WP – Export and Import CSV and XML files to WordPress plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-12894
was published
Nov 21, 2025
Tanium addressed an arbitrary file deletion vulnerability in TanOS.
Moderate
Unreviewed
CVE-2025-13225
was published
Nov 19, 2025
IBM Cognos Analytics Certified Containers 12.1.0 could disclose package parameter information due...
Moderate
Unreviewed
CVE-2025-33150
was published
Nov 10, 2025
FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and...
Moderate
Unreviewed
CVE-2025-58152
was published
Oct 31, 2025
Contrast has insecure LUKS2 persistent storage partitions may be opened and used
Moderate
GHSA-f5p4-p5q5-jv3h
was published
for
github.com/edgelesssys/contrast
(Go)
Oct 28, 2025
Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
Moderate
CVE-2025-11965
was published
for
io.vertx:vertx-web
(Maven)
Oct 22, 2025
HCL Unica Platform is affected by unprotected files due to improper access controls. These...
Moderate
Unreviewed
CVE-2025-31996
was published
Oct 13, 2025
In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an...
Moderate
Unreviewed
CVE-2025-11371
was published
Oct 9, 2025
A vulnerability in the command-line interface of EdgeConnect SD-WAN could allow an authenticated...
Moderate
Unreviewed
CVE-2025-37130
was published
Sep 17, 2025
copyparty: Sharing a single file does not fully restrict access to other files in source folder
Moderate
CVE-2025-58753
was published
for
copyparty
(pip)
Sep 9, 2025
CData API Server MySQL Misconfiguration Information Disclosure Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-9273
was published
Sep 2, 2025
Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier...
Moderate
Unreviewed
CVE-2025-52460
was published
Aug 28, 2025
Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry
Moderate
CVE-2025-43758
was published
for
com.liferay:com.liferay.frontend.js.web
(Maven)
Aug 22, 2025
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an...
Moderate
Unreviewed
CVE-2025-51818
was published
Aug 21, 2025
Liferay Portal Unauthenticated File Access via URL
Moderate
CVE-2025-43749
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Aug 20, 2025
Dell SmartFabric OS10 Software, versions prior to 10.6.0.5 contains a Files or Directories...
Moderate
Unreviewed
CVE-2025-30103
was published
Jul 30, 2025
A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when...
Moderate
Unreviewed
CVE-2025-0620
was published
Jun 6, 2025
The web portal on airpointer 2.4.107-2 was vulnerable local file inclusion. A malicious user with...
Moderate
Unreviewed
CVE-2025-4634
was published
May 30, 2025
Markdownify MCP Server allows attackers to read arbitrary files
Moderate
CVE-2025-5273
was published
for
mcp-markdownify-server
(npm)
May 29, 2025
The TeleMessage service through 2025-05-05 is based on a JSP application in which the heap...
Moderate
Unreviewed
CVE-2025-48928
was published
May 28, 2025
A vulnerability classified as critical was found in SourceCodester Client Database Management...
Moderate
Unreviewed
CVE-2025-4909
was published
May 19, 2025
The Secure Downloads WordPress plugin before 1.2.3 is vulnerable does not properly restrict which...
Moderate
Unreviewed
CVE-2024-8031
was published
May 15, 2025
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear...
Moderate
Unreviewed
CVE-2025-2651
was published
Mar 23, 2025
The Download Manager WordPress plugin before 3.3.07 doesn't prevent directory listing on web...
Moderate
Unreviewed
CVE-2024-13126
was published
Mar 16, 2025
ProTip!
Advisories are also available from the
GraphQL API