GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,825
Erlang
36
GitHub Actions
32
Go
2,417
Maven
5,000+
npm
4,054
NuGet
723
pip
3,845
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
2,938 advisories
Filter by severity
Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image...
Critical
Unreviewed
CVE-2025-28951
was published
Jul 4, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub allows...
Critical
Unreviewed
CVE-2025-30933
was published
Jul 4, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery allows...
Critical
Unreviewed
CVE-2025-49414
was published
Jul 4, 2025
Unrestricted Upload of File with Dangerous Type vulnerability in WPCenter AiBud WP allows Upload...
Critical
Unreviewed
CVE-2025-23968
was published
Jul 3, 2025
Marvell QConvergeConsole getFileFromURL Unrestricted File Upload Remote Code Execution...
Critical
Unreviewed
CVE-2025-6802
was published
Jul 7, 2025
The ZoomSounds plugin before 6.05 contains a PHP file allowing unauthenticated users to upload an...
Critical
Unreviewed
CVE-2021-4457
was published
Jun 26, 2025
A vulnerability has been identified in TIA Project-Server (All versions < V2.1.1), TIA Project...
Moderate
Unreviewed
CVE-2025-27127
was published
Jul 8, 2025
A vulnerability classified as critical has been found in Project Worlds Online Time Table...
Moderate
Unreviewed
CVE-2025-3041
was published
Apr 1, 2025
A vulnerability classified as critical was found in Project Worlds Online Time Table Generator 1...
Moderate
Unreviewed
CVE-2025-3042
was published
Apr 1, 2025
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been rated as...
Moderate
Unreviewed
CVE-2025-3040
was published
Apr 1, 2025
The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to arbitrary file...
Critical
Unreviewed
CVE-2024-8856
was published
Nov 16, 2024
A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-6843
was published
Jun 29, 2025
IBM Analytics Content Hub 2.0, 2.1, 2.2, and 2.3 could be vulnerable to malicious file upload by...
Moderate
Unreviewed
CVE-2024-39752
was published
Jul 10, 2025
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to...
High
Unreviewed
CVE-2025-34097
was published
Jul 10, 2025
A vulnerability was found in code-projects Car Rental System 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-6667
was published
Jun 26, 2025
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file...
High
Unreviewed
CVE-2025-6057
was published
Jul 12, 2025
The WPBookit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file...
Critical
Unreviewed
CVE-2025-6058
was published
Jul 12, 2025
The BeeTeam368 Extensions plugin for WordPress is vulnerable to arbitrary file uploads due to...
High
Unreviewed
CVE-2025-6423
was published
Jul 12, 2025
The AIT CSV import/export plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2020-36849
was published
Jul 12, 2025
The Simple-File-List Plugin for WordPress is vulnerable to Remote Code Execution in versions up...
Critical
Unreviewed
CVE-2020-36847
was published
Jul 12, 2025
qdrant/qdrant is vulnerable to a path traversal and arbitrary file upload vulnerability via the `...
Critical
Unreviewed
CVE-2024-2221
was published
Apr 10, 2024
If a user saved a response from the Network tab in Devtools using the Save As context menu option...
High
Unreviewed
CVE-2025-6435
was published
Jun 26, 2025
The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder. plugin...
Critical
Unreviewed
CVE-2025-7340
was published
Jul 15, 2025
A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-7470
was published
Jul 12, 2025
Apache Struts file upload logic is flawed
Critical
CVE-2024-53677
was published
for
org.apache.struts:struts2-core
(Maven)
Dec 11, 2024
ProTip!
Advisories are also available from the
GraphQL API