GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,652
Erlang
34
GitHub Actions
26
Go
2,257
Maven
5,000+
npm
3,909
NuGet
704
pip
3,680
Pub
12
RubyGems
915
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
98,900 advisories
Filter by severity
Cross-Site Request Forgery (CSRF) vulnerability in Steve Availability Calendar allows Stored XSS....
High
Unreviewed
CVE-2025-46528
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Shamim Hasan Custom Functions Plugin allows...
High
Unreviewed
CVE-2025-46512
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in ldrumm Unsafe Mimetypes allows Stored XSS....
High
Unreviewed
CVE-2025-46507
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in milat Milat jQuery Automatic Popup allows...
High
Unreviewed
CVE-2025-46514
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in stesvis WP Filter Post Category allows Stored...
High
Unreviewed
CVE-2025-46524
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in silencecm Twitter Card Generator allows Stored...
High
Unreviewed
CVE-2025-46516
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Billy Bryant Tabs allows Stored XSS. This...
High
Unreviewed
CVE-2025-46522
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in alphasis Related Posts via Taxonomies allows...
High
Unreviewed
CVE-2025-46520
was published
Apr 24, 2025
Insufficient URI protocol whitelist in HCL Leap
allows script injection through query parameters.
High
Unreviewed
CVE-2023-37534
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in HuangYe WuDeng Hacklog Remote Attachment...
High
Unreviewed
CVE-2025-46530
was published
Apr 24, 2025
Deserialization of Untrusted Data vulnerability in Michael Cannon Flickr Shortcode Importer...
High
Unreviewed
CVE-2025-46481
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46502
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Pham Thanh Call Now PHT Blog allows Stored XSS...
High
Unreviewed
CVE-2025-46492
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Navegg Navegg Analytics allows Stored XSS....
High
Unreviewed
CVE-2025-46497
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46499
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in harrysudana Contact Form 7 Calendar allows...
High
Unreviewed
CVE-2025-46510
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Olar Marius Vasaio QR Code allows Stored XSS....
High
Unreviewed
CVE-2025-46504
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao Advanced lazy load allows Stored XSS...
High
Unreviewed
CVE-2025-46508
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Lora77 WpZon – Amazon Affiliate Plugin allows...
High
Unreviewed
CVE-2025-46506
was published
Apr 24, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-46449
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Casey Johnson Loan Calculator allows Stored...
High
Unreviewed
CVE-2025-46442
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in x000x occupancyplan allows Stored XSS. This...
High
Unreviewed
CVE-2025-46450
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Olav Kolbu Google News allows Stored XSS. This...
High
Unreviewed
CVE-2025-46452
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in digontoahsan Wp Custom CMS Block allows Stored...
High
Unreviewed
CVE-2025-46457
was published
Apr 24, 2025
Cross-Site Request Forgery (CSRF) vulnerability in John Weissberg Print Science Designer allows...
High
Unreviewed
CVE-2025-46465
was published
Apr 24, 2025
ProTip!
Advisories are also available from the
GraphQL API