GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
95,687 advisories
Filter by severity
An issue in TPLINK TL-WPA 8630 TL-WPA8630(US)_V2_2.0.4 Build 20230427 allows a remote attacker to...
High
Unreviewed
CVE-2024-57357
was published
Feb 8, 2025
SQL injection vulnerability in Beijing Guoju Information Technology Co., Ltd JeecgBoot v.3.7.2...
High
Unreviewed
CVE-2024-57606
was published
Feb 8, 2025
An issue in Brainasoft Braina v2.8 allows a remote attacker to obtain sensitive information via...
High
Unreviewed
CVE-2024-55272
was published
Feb 8, 2025
An improper access control vulnerability may allow privilege escalation.This issue affects:
*...
High
Unreviewed
CVE-2022-26389
was published
Feb 7, 2025
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions...
High
Unreviewed
CVE-2024-7419
was published
Feb 7, 2025
The WP All Import Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions...
High
Unreviewed
CVE-2024-9664
was published
Feb 7, 2025
Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This...
High
Unreviewed
CVE-2025-1108
was published
Feb 7, 2025
An issue has been discovered in the gitlab-web-ide-vscode-fork component distributed over CDN...
High
Unreviewed
CVE-2024-10383
was published
Feb 7, 2025
A vulnerability, which was classified as problematic, was found in D-Link DIR-823X 240126/240802....
High
Unreviewed
CVE-2025-1103
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in djjmz Simple Auto Tag allows Stored XSS. This...
High
Unreviewed
CVE-2025-25153
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments allows Stored...
High
Unreviewed
CVE-2025-25156
was published
Feb 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-25155
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in scweber Custom Comment Notifications allows...
High
Unreviewed
CVE-2025-25154
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in gabrieldarezzo InLocation allows Stored XSS....
High
Unreviewed
CVE-2025-25166
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Mark Barnes Style Tweaker allows Stored XSS....
High
Unreviewed
CVE-2025-25160
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow allows Stored XSS....
High
Unreviewed
CVE-2025-25152
was published
Feb 7, 2025
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
High
Unreviewed
CVE-2025-25163
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Danillo Nunes Login-box allows Stored XSS....
High
Unreviewed
CVE-2025-25149
was published
Feb 7, 2025
Missing Authorization vulnerability in blackandwhitedigital BookPress – For Book Authors allows...
High
Unreviewed
CVE-2025-25167
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in blackandwhitedigital BookPress – For Book...
High
Unreviewed
CVE-2025-25168
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Phillip.Gooch Auto SEO allows Stored XSS. This...
High
Unreviewed
CVE-2025-25147
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in Scriptonite Simple User Profile allows Stored...
High
Unreviewed
CVE-2025-25140
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in ElbowRobo Read More Copy Link allows Stored...
High
Unreviewed
CVE-2025-25148
was published
Feb 7, 2025
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File...
High
Unreviewed
CVE-2025-25141
was published
Feb 7, 2025
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')...
High
Unreviewed
CVE-2025-25159
was published
Feb 7, 2025
ProTip!
Advisories are also available from the
GraphQL API