GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
24,510 advisories
Filter by severity
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-0316
was published
Feb 9, 2025
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via...
Critical
Unreviewed
CVE-2024-55215
was published
Feb 8, 2025
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an...
Critical
Unreviewed
CVE-2025-1107
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP allows...
Critical
Unreviewed
CVE-2025-25106
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites allows Cross Site...
Critical
Unreviewed
CVE-2025-25107
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites allows Cross Site...
Critical
Unreviewed
CVE-2025-25101
was published
Feb 7, 2025
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and...
Critical
Unreviewed
CVE-2025-1077
was published
Feb 7, 2025
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-1061
was published
Feb 7, 2025
Multiple Elber products are affected by an authentication bypass
vulnerability which allows...
Critical
Unreviewed
CVE-2025-0674
was published
Feb 7, 2025
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >=...
Critical
Unreviewed
CVE-2025-22992
was published
Feb 6, 2025
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload...
Critical
Unreviewed
CVE-2024-57668
was published
Feb 6, 2025
WhoDB has a path traversal opening Sqlite3 database
Critical
CVE-2025-24786
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Critical
Unreviewed
CVE-2022-40916
was published
Feb 6, 2025
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking...
Critical
Unreviewed
CVE-2024-57430
was published
Feb 6, 2025
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists...
Critical
Unreviewed
CVE-2024-57428
was published
Feb 6, 2025
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML...
Critical
Unreviewed
CVE-2024-39272
was published
Feb 6, 2025
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Critical
CVE-2025-24981
was published
for
@nuxtjs/mdc
(npm)
Feb 6, 2025
Multiple rtmpdump vulnerabilities
Critical
GHSA-vrpv-vw92-328g
was published
for
rudloff/rtmpdump-bin
(Composer)
Feb 6, 2025
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x,...
Critical
Unreviewed
CVE-2023-5878
was published
Feb 6, 2025
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an...
Critical
Unreviewed
CVE-2025-0982
was published
Feb 6, 2025
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB...
Critical
Unreviewed
CVE-2024-51547
was published
Feb 6, 2025
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker...
Critical
Unreviewed
CVE-2024-51450
was published
Feb 6, 2025
OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for...
Critical
Unreviewed
CVE-2025-1066
was published
Feb 6, 2025
utils-extend Prototype Pollution
Critical
CVE-2024-57077
was published
for
utils-extend
(npm)
Feb 6, 2025
Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary...
Critical
Unreviewed
CVE-2024-57520
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API