GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
131,674 advisories
Filter by severity
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49309
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49311
was published
Jun 6, 2025
Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows...
Moderate
Unreviewed
CVE-2025-49320
was published
Jun 6, 2025
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Automattic Newspack...
Moderate
Unreviewed
CVE-2025-49325
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49310
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49318
was published
Jun 6, 2025
Missing Authorization vulnerability in PickPlugins Job Board Manager allows Exploiting...
Moderate
Unreviewed
CVE-2025-49324
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49322
was published
Jun 6, 2025
Missing Authorization vulnerability in cmoreira Team Showcase allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49248
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Bill Minozzi WP Tools allows Cross Site...
Moderate
Unreviewed
CVE-2025-49273
was published
Jun 6, 2025
Missing Authorization vulnerability in sergiotrinity Trinity Audio allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49272
was published
Jun 6, 2025
Missing Authorization vulnerability in cmoreira Testimonials Showcase allows Exploiting...
Moderate
Unreviewed
CVE-2025-49246
was published
Jun 6, 2025
Missing Authorization vulnerability in Mario Peshev WP-CRM System allows Accessing Functionality...
Moderate
Unreviewed
CVE-2025-49270
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA...
Moderate
Unreviewed
CVE-2025-49285
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter allows Cross...
Moderate
Unreviewed
CVE-2025-49269
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in wp-buy WP Maintenance Mode & Site Under...
Moderate
Unreviewed
CVE-2025-49284
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in codepeople Calculated Fields Form allows Cross...
Moderate
Unreviewed
CVE-2025-49291
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in WP Table Builder WP Table Builder allows Cross...
Moderate
Unreviewed
CVE-2025-49286
was published
Jun 6, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Matthias Nordwig Anti-spam, Spam protection,...
Moderate
Unreviewed
CVE-2025-49283
was published
Jun 6, 2025
Missing Authorization vulnerability in add-ons.org PDF for WPForms allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49289
was published
Jun 6, 2025
Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce allows Exploiting...
Moderate
Unreviewed
CVE-2025-49287
was published
Jun 6, 2025
Missing Authorization vulnerability in CodeRevolution Crawlomatic Multisite Scraper Post...
Moderate
Unreviewed
CVE-2025-49293
was published
Jun 6, 2025
Missing Authorization vulnerability in Rustaurius Ultimate WP Mail allows Exploiting Incorrectly...
Moderate
Unreviewed
CVE-2025-49288
was published
Jun 6, 2025
Improper Validation of Specified Quantity in Input vulnerability in Cozmoslabs Profile Builder...
Moderate
Unreviewed
CVE-2025-49292
was published
Jun 6, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
Moderate
Unreviewed
CVE-2025-49299
was published
Jun 6, 2025
ProTip!
Advisories are also available from the
GraphQL API