GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,038
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,038 advisories
Filter by severity
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept...
Moderate
Unreviewed
CVE-2025-8848
was published
Oct 22, 2025
The The Discussion Board – WordPress Forum Plugin plugin for WordPress is vulnerable to arbitrary...
Moderate
Unreviewed
CVE-2025-8483
was published
Oct 25, 2025
A vulnerability was found in yanyutao0402 ChanCMS up to 3.3.2. This vulnerability affects the...
Moderate
Unreviewed
CVE-2025-11905
was published
Oct 17, 2025
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session...
Moderate
Unreviewed
CVE-2024-8069
was published
Nov 12, 2024
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug...
Moderate
Unreviewed
CVE-2024-20359
was published
Apr 24, 2024
[PROBLEMTYPE] in [COMPONENT] in [VENDOR] [PRODUCT] [VERSION] on [PLATFORMS] allows [ATTACKER] to ...
Moderate
Unreviewed
CVE-2023-6548
was published
Jan 17, 2024
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up...
Moderate
Unreviewed
CVE-2021-22204
was published
May 24, 2022
A code injection vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker to...
Moderate
Unreviewed
CVE-2020-8218
was published
May 24, 2022
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an...
Moderate
Unreviewed
CVE-2022-41223
was published
Nov 22, 2022
** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-610 devices allow Remote Command Execution via the cmd...
Moderate
Unreviewed
CVE-2020-9377
was published
May 24, 2022
bagisto has Server Side Template Injection (SSTI) in Product Description
Moderate
CVE-2025-62416
was published
for
bagisto/bagisto
(Composer)
Oct 16, 2025
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects...
Moderate
Unreviewed
CVE-2025-3842
was published
Apr 21, 2025
An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in...
Moderate
Unreviewed
CVE-2025-31365
was published
Oct 14, 2025
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript...
Moderate
Unreviewed
CVE-2025-42901
was published
Oct 14, 2025
A vulnerability was detected in ILIAS up to 8.23/9.13/10.1. Affected by this vulnerability is an...
Moderate
Unreviewed
CVE-2025-11344
was published
Oct 6, 2025
A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown...
Moderate
Unreviewed
CVE-2025-10993
was published
Sep 26, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce...
Moderate
Unreviewed
CVE-2025-60114
was published
Sep 26, 2025
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due...
Moderate
Unreviewed
CVE-2025-5717
was published
Sep 23, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Tareq Hasan WP User...
Moderate
Unreviewed
CVE-2025-58673
was published
Sep 22, 2025
A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This...
Moderate
Unreviewed
CVE-2025-7101
was published
Jul 7, 2025
SimStudioAI: A function in route.ts is vulnerable to Code Injection
Moderate
CVE-2025-10097
was published
for
simstudio
(npm)
Sep 8, 2025
Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
Moderate
CVE-2025-35036
was published
for
org.hibernate.validator:hibernate-validator
(Maven)
Jun 3, 2025
The The WP-Members Membership Plugin plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2025-9489
was published
Sep 9, 2025
Electron has ASAR Integrity Bypass via resource modification
Moderate
CVE-2025-55305
was published
for
electron
(npm)
Sep 3, 2025
lychee link checking action affected by arbitrary code injection in composite action
Moderate
CVE-2024-48908
was published
for
lycheeverse/lychee-action
(GitHub Actions)
Aug 28, 2025
ProTip!
Advisories are also available from the
GraphQL API