GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,680
Maven
5,000+
npm
4,308
NuGet
760
pip
4,080
Pub
12
RubyGems
958
Rust
1,061
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,043 advisories
Filter by severity
esm.sh CDN service has JS Template Literal Injection in CSS-to-JavaScript
Moderate
CVE-2025-65026
was published
for
github.com/esm-dev/esm.sh
(Go)
Nov 19, 2025
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks...
Moderate
Unreviewed
CVE-2025-63693
was published
Nov 18, 2025
The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-7711
was published
Nov 18, 2025
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of...
Moderate
Unreviewed
CVE-2024-48829
was published
Nov 12, 2025
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a...
Moderate
Unreviewed
CVE-2025-42895
was published
Nov 11, 2025
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-8483
was published
Oct 25, 2025
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept...
Moderate
Unreviewed
CVE-2025-8848
was published
Oct 22, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-11905
was published
Oct 17, 2025
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in...
Moderate
Unreviewed
CVE-2025-31365
was published
Oct 14, 2025
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript...
Moderate
Unreviewed
CVE-2025-42901
was published
Oct 14, 2025
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an...
Moderate
Unreviewed
CVE-2025-11344
was published
Oct 6, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce...
Moderate
Unreviewed
CVE-2025-60114
was published
Sep 26, 2025
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-10993
was published
Sep 26, 2025
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due...
Moderate
Unreviewed
CVE-2025-5717
was published
Sep 23, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Tareq Hasan WP User...
Moderate
Unreviewed
CVE-2025-58673
was published
Sep 22, 2025
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2025-9489
was published
Sep 9, 2025
SimStudioAI: A function in route.ts is vulnerable to Code Injection
Moderate
CVE-2025-10097
was published
for
simstudio
(npm)
Sep 8, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18...
Moderate
Unreviewed
CVE-2025-5101
was published
Aug 27, 2025
Craft CMS Potential Remote Code Execution via Twig SSTI
Moderate
CVE-2025-57811
was published
for
craftcms/cms
(Composer)
Aug 25, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone...
Moderate
Unreviewed
CVE-2025-54019
was published
Aug 20, 2025
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile &...
Moderate
Unreviewed
CVE-2025-8878
was published
Aug 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS...
Moderate
Unreviewed
CVE-2025-7961
was published
Aug 15, 2025
ProTip!
Advisories are also available from the
GraphQL API