GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,820
Erlang
36
GitHub Actions
32
Go
2,412
Maven
5,000+
npm
4,050
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,004
Swift
38
Unreviewed advisories
All unreviewed
5,000+
4,551 advisories
Filter by severity
A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0...
Critical
Unreviewed
CVE-2025-44881
was published
May 20, 2025
Langroid has a Code Injection vulnerability in LanceDocChatAgent through vector_store
High
CVE-2025-46725
was published
for
langroid
(pip)
May 20, 2025
Langroid has a Code Injection vulnerability in TableChatAgent
Critical
CVE-2025-46724
was published
for
langroid
(pip)
May 20, 2025
A vulnerability was found in weibocom rill-flow 0.1.18. It has been classified as critical....
Moderate
Unreviewed
CVE-2025-4866
was published
May 18, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP...
Moderate
Unreviewed
CVE-2025-48119
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG Lite...
Moderate
Unreviewed
CVE-2025-48120
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG...
Moderate
Unreviewed
CVE-2025-47562
was published
May 16, 2025
Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings...
Critical
Unreviewed
CVE-2025-47916
was published
May 16, 2025
The UiPress lite | Effortless custom dashboards, admin themes and pages plugin for WordPress is...
High
Unreviewed
CVE-2025-3053
was published
May 15, 2025
mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target...
Critical
Unreviewed
CVE-2025-32363
was published
May 14, 2025
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an...
Moderate
Unreviewed
CVE-2025-0134
was published
May 14, 2025
Cosmos EVM Allows Partial Precompile State Writes
High
GHSA-mjfq-3qr2-6g84
was published
for
github.com/cosmos/evm
(Go)
May 14, 2025
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to...
High
Unreviewed
CVE-2024-54780
was published
May 14, 2025
Apache IoTDB Vulnerable to Remote Code Execution
Critical
CVE-2024-24780
was published
for
apache-iotdb
(Maven)
May 14, 2025
EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via...
Critical
Unreviewed
CVE-2025-45857
was published
May 13, 2025
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on...
High
Unreviewed
CVE-2025-4428
was published
May 13, 2025
SAP S/4HANA Cloud Private Edition or on Premise (SCM Master Data Layer (MDL)) allows an...
High
Unreviewed
CVE-2025-43010
was published
May 13, 2025
OZI-Project/ozi-publish Code Injection vulnerability
Moderate
CVE-2025-47271
was published
for
OZI-Project/publish
(GitHub Actions)
May 12, 2025
An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin...
Critical
Unreviewed
CVE-2025-44022
was published
May 12, 2025
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management...
Critical
Unreviewed
CVE-2025-46191
was published
May 9, 2025
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a...
Critical
Unreviewed
CVE-2025-29509
was published
May 9, 2025
Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.
Critical
Unreviewed
CVE-2025-28203
was published
May 9, 2025
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute...
Moderate
Unreviewed
CVE-2025-28201
was published
May 9, 2025
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the...
Critical
Unreviewed
CVE-2025-26845
was published
May 8, 2025
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-4208
was published
May 8, 2025
ProTip!
Advisories are also available from the
GraphQL API