GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
24,517 advisories
Filter by severity
The WP Foodbakery plugin for WordPress is vulnerable to arbitrary file uploads due to...
Critical
Unreviewed
CVE-2024-13011
was published
Feb 10, 2025
The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-0316
was published
Feb 9, 2025
An issue in trojan v.2.0.0 through v.2.15.3 allows a remote attacker to escalate privileges via...
Critical
Unreviewed
CVE-2024-55215
was published
Feb 8, 2025
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and...
Critical
Unreviewed
CVE-2024-57707
was published
Feb 7, 2025
Incorrect Access Control in the Preview Function of Gleamtech FileVista 9.2.0.0 allows remote...
Critical
Unreviewed
CVE-2024-57249
was published
Feb 7, 2025
Unverified password change vulnerability in Janto, versions prior to r12. This could allow an...
Critical
Unreviewed
CVE-2025-1107
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in FancyWP Starter Templates by FancyWP allows...
Critical
Unreviewed
CVE-2025-25106
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in sainwp OneStore Sites allows Cross Site...
Critical
Unreviewed
CVE-2025-25107
was published
Feb 7, 2025
Cross-Site Request Forgery (CSRF) vulnerability in MetricThemes Munk Sites allows Cross Site...
Critical
Unreviewed
CVE-2025-25101
was published
Feb 7, 2025
A security vulnerability has been identified in the IBL Software Engineering Visual Weather and...
Critical
Unreviewed
CVE-2025-1077
was published
Feb 7, 2025
The Nextend Social Login Pro plugin for WordPress is vulnerable to authentication bypass in...
Critical
Unreviewed
CVE-2025-1061
was published
Feb 7, 2025
Multiple Elber products are affected by an authentication bypass
vulnerability which allows...
Critical
Unreviewed
CVE-2025-0674
was published
Feb 7, 2025
A SQL Injection vulnerability exists in the /feed/insert.json endpoint of the Emoncms project >=...
Critical
Unreviewed
CVE-2025-22992
was published
Feb 6, 2025
In Code-projects Shopping Portal v1.0, the insert-product.php page has an arbitrary file upload...
Critical
Unreviewed
CVE-2024-57668
was published
Feb 6, 2025
WhoDB has a path traversal opening Sqlite3 database
Critical
CVE-2025-24786
was published
for
github.com/clidey/whodb/core
(Go)
Feb 6, 2025
Tiny File Manager v2.4.7 and below is vulnerable to session fixation.
Critical
Unreviewed
CVE-2022-40916
was published
Feb 6, 2025
An SQL injection vulnerability in the pjActionGetUser function of PHPJabbers Cinema Booking...
Critical
Unreviewed
CVE-2024-57430
was published
Feb 6, 2025
A stored cross-site scripting (XSS) vulnerability in PHPJabbers Cinema Booking System v2.0 exists...
Critical
Unreviewed
CVE-2024-57428
was published
Feb 6, 2025
A cross-site scripting (xss) vulnerability exists in the dataset upload functionality of ClearML...
Critical
Unreviewed
CVE-2024-39272
was published
Feb 6, 2025
Built-in SMS-configuration command in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1...
Critical
Unreviewed
CVE-2024-36555
was published
Feb 6, 2025
Forever KidsWatch Call Me KW-50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever...
Critical
Unreviewed
CVE-2024-36554
was published
Feb 6, 2025
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever...
Critical
Unreviewed
CVE-2024-36556
was published
Feb 6, 2025
Parsed HTML anchor links in Markdown provided to parseMarkdown can result in XSS in @nuxtjs/mdc
Critical
CVE-2025-24981
was published
for
@nuxtjs/mdc
(npm)
Feb 6, 2025
Multiple rtmpdump vulnerabilities
Critical
GHSA-vrpv-vw92-328g
was published
for
rudloff/rtmpdump-bin
(Composer)
Feb 6, 2025
Honeywell OneWireless
Wireless Device Manager (WDM) for the following versions R310.x, R320.x,...
Critical
Unreviewed
CVE-2023-5878
was published
Feb 6, 2025
ProTip!
Advisories are also available from the
GraphQL API