GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,819
Erlang
36
GitHub Actions
32
Go
2,410
Maven
5,000+
npm
4,046
NuGet
723
pip
3,842
Pub
12
RubyGems
933
Rust
1,003
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
124,434 advisories
Filter by severity
A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as...
Moderate
Unreviewed
CVE-2025-8434
was published
Aug 1, 2025
A vulnerability was found in code-projects Document Management System 1.0 and classified as...
Moderate
Unreviewed
CVE-2025-8433
was published
Aug 1, 2025
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting...
Moderate
Unreviewed
CVE-2025-7845
was published
Aug 1, 2025
Quantum SuperLoader 3 V94.0 005E.0h devices allow attackers to access the hardcoded fa account...
Moderate
Unreviewed
CVE-2019-19145
was published
Aug 1, 2025
In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic...
Moderate
Unreviewed
CVE-2025-53399
was published
Aug 1, 2025
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical....
Moderate
Unreviewed
CVE-2025-8431
was published
Aug 1, 2025
A vulnerability was discovered in the storage policy for certain sets of sensitive credential...
Moderate
Unreviewed
CVE-2025-37110
was published
Jul 31, 2025
A vulnerability was discovered in the storage policy for certain sets of authentication keys in...
Moderate
Unreviewed
CVE-2025-37111
was published
Jul 31, 2025
NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs,...
Moderate
Unreviewed
CVE-2025-23289
was published
Jul 31, 2025
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the...
Moderate
Unreviewed
CVE-2025-37112
was published
Jul 31, 2025
Sielox AnyWare v2.1.2 was discovered to contain a SQL injection vulnerability via the email...
Moderate
Unreviewed
CVE-2024-34327
was published
Jul 31, 2025
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in...
Moderate
Unreviewed
CVE-2025-50866
was published
Jul 31, 2025
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom...
Moderate
Unreviewed
CVE-2025-50867
was published
Jul 31, 2025
OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add...
Moderate
Unreviewed
CVE-2025-54832
was published
Jul 31, 2025
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows attackers to bypass account...
Moderate
Unreviewed
CVE-2025-54833
was published
Jul 31, 2025
OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote...
Moderate
Unreviewed
CVE-2025-54834
was published
Jul 31, 2025
A vulnerability has been found in code-projects Vehicle Management 1.0 and classified as critical...
Moderate
Unreviewed
CVE-2025-8409
was published
Jul 31, 2025
A Insertion of Sensitive Information into Log File vulnerability in SUSE Multi Linux Manager...
Moderate
Unreviewed
CVE-2025-46809
was published
Jul 31, 2025
A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute...
Moderate
Unreviewed
CVE-2025-50848
was published
Jul 31, 2025
Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add...
Moderate
Unreviewed
CVE-2025-50847
was published
Jul 31, 2025
An open redirect in Sielox AnyWare v2.1.2 allows attackers to execute a man-in-the-middle attack...
Moderate
Unreviewed
CVE-2024-34328
was published
Jul 31, 2025
A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS...
Moderate
Unreviewed
CVE-2025-50270
was published
Jul 31, 2025
A stack-based buffer overflow vulnerability exists in the tmUnblock.cgi endpoint of the Linksys...
Moderate
Unreviewed
CVE-2014-125122
was published
Jul 31, 2025
A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06...
Moderate
Unreviewed
CVE-2025-51569
was published
Jul 31, 2025
ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration...
Moderate
Unreviewed
CVE-2025-29557
was published
Jul 31, 2025
ProTip!
Advisories are also available from the
GraphQL API