GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,768
Erlang
35
GitHub Actions
29
Go
2,332
Maven
5,000+
npm
3,965
NuGet
713
pip
3,748
Pub
12
RubyGems
921
Rust
975
Swift
38
Unreviewed advisories
All unreviewed
5,000+
108,378 advisories
Filter by severity
The Real Estate 7 WordPress theme for WordPress is vulnerable to arbitrary file uploads due to...
High
Unreviewed
CVE-2025-2891
was published
Apr 1, 2025
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via...
High
Unreviewed
CVE-2024-12278
was published
Apr 1, 2025
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Ventura 13...
High
Unreviewed
CVE-2025-24234
was published
Apr 1, 2025
The issue was addressed with improved memory handling. This issue is fixed in visionOS 2.4, macOS...
High
Unreviewed
CVE-2025-24243
was published
Apr 1, 2025
A logic issue was addressed with improved file handling. This issue is fixed in macOS Ventura 13...
High
Unreviewed
CVE-2025-24170
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30917
was published
Apr 1, 2025
Debug Messages Revealing Unnecessary Information vulnerability in TLA Media GTM Kit allows...
High
Unreviewed
CVE-2025-31001
was published
Apr 1, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-31024
was published
Apr 1, 2025
Deserialization of Untrusted Data vulnerability in MDJM MDJM Event Management allows Object...
High
Unreviewed
CVE-2025-31074
was published
Apr 1, 2025
Missing Authorization vulnerability in YayCommerce YayExtra allows Exploiting Incorrectly...
High
Unreviewed
CVE-2025-31415
was published
Apr 1, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-30882
was published
Apr 1, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-30878
was published
Apr 1, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-30910
was published
Apr 1, 2025
Missing Authorization vulnerability in JoomSky JS Help Desk allows Exploiting Incorrectly...
High
Unreviewed
CVE-2025-30880
was published
Apr 1, 2025
Local privilege escalation through insecure DCOM configuration in Valmet DNA versions prior to...
High
Unreviewed
CVE-2025-0416
was published
Apr 1, 2025
The Awesome Support – WordPress HelpDesk & Support Plugin plugin for WordPress is vulnerable to...
High
Unreviewed
CVE-2024-13567
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30544
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30547
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30548
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30559
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30579
was published
Apr 1, 2025
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
High
Unreviewed
CVE-2025-30589
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30563
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30607
was published
Apr 1, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-30614
was published
Apr 1, 2025
ProTip!
Advisories are also available from the
GraphQL API