GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
902 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase...
Moderate
Unreviewed
CVE-2025-49250
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41362
was published
Jun 6, 2025
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability...
Moderate
Unreviewed
CVE-2025-41365
was published
Jun 6, 2025
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This...
Moderate
Unreviewed
CVE-2025-5151
was published
May 25, 2025
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker...
Moderate
Unreviewed
CVE-2023-37518
was published
Jan 30, 2024
Improper Control of Generation of Code ('Code Injection') vulnerability in RS WP THEMES RS WP...
Moderate
Unreviewed
CVE-2025-48119
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG Lite...
Moderate
Unreviewed
CVE-2025-48120
was published
May 16, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in RomanCode MapSVG...
Moderate
Unreviewed
CVE-2025-47562
was published
May 16, 2025
Brandon
Rothel from QED Secure Solutions has found that the VAPIX API tcptest.cgi
did not have a...
Moderate
Unreviewed
CVE-2023-5677
was published
Feb 5, 2024
A code injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an...
Moderate
Unreviewed
CVE-2025-0134
was published
May 14, 2025
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical....
Moderate
Unreviewed
CVE-2025-4022
was published
Apr 28, 2025
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0....
Moderate
Unreviewed
CVE-2025-3982
was published
Apr 27, 2025
An issue in Victure RX1800 EN_V1.0.0_r12_110933 allows physically proximate attackers to execute...
Moderate
Unreviewed
CVE-2025-28201
was published
May 9, 2025
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is...
Moderate
Unreviewed
CVE-2025-4208
was published
May 8, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member...
Moderate
Unreviewed
CVE-2025-47691
was published
May 7, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in GS Plugins GS...
Moderate
Unreviewed
CVE-2025-47481
was published
May 7, 2025
Multiple plugins and/or themes for WordPress are vulnerable to unauthorized access due to a...
Moderate
Unreviewed
CVE-2024-13420
was published
May 2, 2025
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue...
Moderate
Unreviewed
CVE-2025-3563
was published
Apr 14, 2025
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET...
Moderate
Unreviewed
CVE-2024-32499
was published
Apr 28, 2025
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
Moderate
Unreviewed
CVE-2023-42404
was published
Apr 28, 2025
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in...
Moderate
Unreviewed
CVE-2024-13812
was published
Apr 26, 2025
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been...
Moderate
Unreviewed
CVE-2025-3164
was published
Apr 3, 2025
A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR...
Moderate
Unreviewed
CVE-2025-0618
was published
Apr 23, 2025
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all...
Moderate
Unreviewed
CVE-2025-3472
was published
Apr 22, 2025
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment...
Moderate
Unreviewed
CVE-2017-17649
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API