GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
23,854 advisories
Filter by severity
The Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent plugin for...
Critical
Unreviewed
CVE-2025-11499
was published
Nov 1, 2025
The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for...
Critical
Unreviewed
CVE-2025-11833
was published
Nov 1, 2025
Incorrect access control in the realtime.cgi endpoint of Deep Sea Electronics devices DSE855 v1.1...
Critical
Unreviewed
CVE-2025-29270
was published
Oct 31, 2025
ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in...
Critical
Unreviewed
CVE-2025-64348
was published
Oct 31, 2025
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in...
Critical
Unreviewed
CVE-2025-57108
was published
Oct 31, 2025
The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an...
Critical
Unreviewed
CVE-2025-41108
was published
Oct 22, 2025
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP...
Critical
Unreviewed
CVE-2024-55547
was published
Dec 10, 2024
Email Server Certificate Verification Disabled.This issue affects BLU-IC2: through 1.19.5; BLU...
Critical
Unreviewed
CVE-2025-12553
was published
Oct 31, 2025
A malicious actor with access to the management network could exploit a misconfiguration in UniFi...
Critical
Unreviewed
CVE-2025-52665
was published
Oct 31, 2025
Denial of service of the web server through specific requests to this protocol
Critical
Unreviewed
CVE-2025-64388
was published
Oct 31, 2025
The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the...
Critical
Unreviewed
CVE-2025-64385
was published
Oct 31, 2025
Following the sandbox escape in CVE-2025-2783, various Firefox developers identified a similar...
Critical
Unreviewed
CVE-2025-2857
was published
Mar 27, 2025
The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor...
Critical
Unreviewed
CVE-2025-8489
was published
Oct 31, 2025
The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up...
Critical
Unreviewed
CVE-2025-5397
was published
Oct 31, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
Critical
Unreviewed
CVE-2025-6520
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its...
Critical
Unreviewed
CVE-2024-14003
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the...
Critical
Unreviewed
CVE-2024-14008
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user...
Critical
Unreviewed
CVE-2024-13996
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.0.1 contain a privilege escalation vulnerability in the System...
Critical
Unreviewed
CVE-2024-14009
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker...
Critical
Unreviewed
CVE-2024-14005
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.4.2 contain a remote code execution vulnerability in the...
Critical
Unreviewed
CVE-2025-34134
was published
Oct 31, 2025
Nagios XI versions prior to 2024R2 contain a command injection vulnerability in the WinRM plugin....
Critical
Unreviewed
CVE-2025-34284
was published
Oct 31, 2025
Nagios XI versions prior to 2026R1 contain a remote code execution vulnerability in the Core...
Critical
Unreviewed
CVE-2025-34286
was published
Oct 31, 2025
Nagios Fusion versions prior to 2024R2.1 contain a brute-force bypass in the Two-Factor...
Critical
Unreviewed
CVE-2025-34249
was published
Oct 31, 2025
Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where...
Critical
Unreviewed
CVE-2025-34277
was published
Oct 31, 2025
ProTip!
Advisories are also available from the
GraphQL API