GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,476
Erlang
33
GitHub Actions
24
Go
2,207
Maven
5,000+
npm
3,858
NuGet
696
pip
3,639
Pub
12
RubyGems
913
Rust
918
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
249,588 advisories
Filter by severity
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive...
Low
Unreviewed
CVE-2024-55895
was published
Mar 29, 2025
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site...
Moderate
Unreviewed
CVE-2024-11180
was published
Mar 29, 2025
The So-Called Air Quotes plugin for WordPress is vulnerable to arbitrary shortcode execution in...
High
Unreviewed
CVE-2025-2803
was published
Mar 29, 2025
The DAP to Autoresponders Email Syncing plugin for WordPress is vulnerable to Sensitive...
Moderate
Unreviewed
CVE-2025-2840
was published
Mar 29, 2025
The Shortcodes by United Themes plugin for WordPress is vulnerable to arbitrary shortcode...
Moderate
Unreviewed
CVE-2024-13557
was published
Mar 29, 2025
The Checkout Mestres do WP for WooCommerce plugin for WordPress is vulnerable to unauthorized...
Critical
Unreviewed
CVE-2025-2266
was published
Mar 29, 2025
The SoJ SoundSlides plugin for WordPress is vulnerable to arbitrary file uploads due to missing...
High
Unreviewed
CVE-2025-2249
was published
Mar 29, 2025
The Inline Image Upload for BBPress plugin for WordPress is vulnerable to arbitrary file uploads...
High
Unreviewed
CVE-2025-2006
was published
Mar 29, 2025
IBM InfoSphere Information Server 11.7
could allow an authenticated to obtain sensitive...
Moderate
Unreviewed
CVE-2024-51477
was published
Mar 29, 2025
IBM InfoSphere Information Server 11.7 could disclose sensitive user credentials from log files...
Moderate
Unreviewed
CVE-2024-7577
was published
Mar 29, 2025
IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive...
Moderate
Unreviewed
CVE-2024-43186
was published
Mar 29, 2025
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
Unknown
Unreviewed
CVE-2025-28096
was published
Mar 29, 2025
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
Unknown
Unreviewed
CVE-2025-28097
was published
Mar 29, 2025
The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory...
Moderate
Unreviewed
CVE-2025-2781
was published
Mar 29, 2025
The WatchGuard Terminal Services Agent on Windows does not properly configure directory...
Moderate
Unreviewed
CVE-2025-2782
was published
Mar 29, 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection...
Unknown
Unreviewed
CVE-2025-28090
was published
Mar 29, 2025
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
Unknown
Unreviewed
CVE-2025-28094
was published
Mar 29, 2025
ProTip!
Advisories are also available from the
GraphQL API