GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,552
Maven
5,000+
npm
4,224
NuGet
746
pip
3,999
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
5,103 advisories
Filter by severity
The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass...
High
Unreviewed
CVE-2025-8593
was published
Oct 11, 2025
The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing...
Moderate
Unreviewed
CVE-2025-8682
was published
Oct 11, 2025
The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for...
Moderate
Unreviewed
CVE-2025-11380
was published
Oct 11, 2025
Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects...
Unknown
Unreviewed
CVE-2025-9549
was published
Oct 11, 2025
A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects...
Moderate
Unreviewed
CVE-2025-11581
was published
Oct 10, 2025
A weakness has been identified in PowerJob up to 5.1.2. This affects the function list of the...
Moderate
Unreviewed
CVE-2025-11580
was published
Oct 10, 2025
Melis Platform CMS Unauthenticated Admin Account Creation
Critical
CVE-2025-10352
was published
for
melisplatform/melis-core
(Composer)
Oct 8, 2025
A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown...
Moderate
Unreviewed
CVE-2025-11438
was published
Oct 8, 2025
A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown...
Moderate
Unreviewed
CVE-2025-11439
was published
Oct 8, 2025
The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget...
Moderate
Unreviewed
CVE-2025-9029
was published
Oct 4, 2025
The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of...
High
Unreviewed
CVE-2025-9243
was published
Oct 4, 2025
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to...
Moderate
Unreviewed
CVE-2025-11228
was published
Oct 4, 2025
The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of...
Moderate
Unreviewed
CVE-2025-10212
was published
Oct 3, 2025
The Constructor theme for WordPress is vulnerable to unauthorized modification of data due to a...
Moderate
Unreviewed
CVE-2025-9194
was published
Oct 3, 2025
The Custom Searchable Data Entry System plugin for WordPress is vulnerable to unauthenticated...
Critical
Unreviewed
CVE-2020-36852
was published
Oct 1, 2025
Missing Authorization vulnerability in HaruTheme Frames allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60165
was published
Sep 26, 2025
Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO allows Exploiting...
Moderate
Unreviewed
CVE-2025-60166
was published
Sep 26, 2025
Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce allows...
Moderate
Unreviewed
CVE-2025-60159
was published
Sep 26, 2025
Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type allows...
Moderate
Unreviewed
CVE-2025-60116
was published
Sep 26, 2025
Missing Authorization vulnerability in ArtistScope CopySafe Web Protection allows Exploiting...
Moderate
Unreviewed
CVE-2025-60127
was published
Sep 26, 2025
Missing Authorization vulnerability in Yext Yext allows Accessing Functionality Not Properly...
Moderate
Unreviewed
CVE-2025-60129
was published
Sep 26, 2025
Missing Authorization vulnerability in wpshuffle Subscribe to Download allows Exploiting...
Moderate
Unreviewed
CVE-2025-60148
was published
Sep 26, 2025
Missing Authorization vulnerability in netgsm Netgsm allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60143
was published
Sep 26, 2025
Missing Authorization vulnerability in HivePress HivePress Claim Listings allows Exploiting...
Moderate
Unreviewed
CVE-2025-60122
was published
Sep 26, 2025
Missing Authorization vulnerability in Roxnor EmailKit allows Exploiting Incorrectly Configured...
Moderate
Unreviewed
CVE-2025-60106
was published
Sep 26, 2025
ProTip!
Advisories are also available from the
GraphQL API